setup-deploy
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several local utilities located in
~/.claude/skills/gstack/bin/for session management, telemetry, and project context recovery. These includegstack-skill-start,gstack-slug, andgstack-learnings-log. These tools are part of the vendor's infrastructure for the gstack system. - [INDIRECT_PROMPT_INJECTION]: The skill reads external configuration files such as
fly.toml,render.yaml, and GitHub Actions workflow files to detect deployment platforms. While these files are local to the user's project, their content influences the agent's behavior. The skill mitigates risks by usingAskUserQuestionto confirm all inferred settings with the user before persisting them toCLAUDE.md. - [DATA_EXFILTRATION]: The skill uses
curlto perform health checks against inferred or user-provided production URLs. It includes explicit instructions to redact sensitive information, such as showing only the first few characters of environment variables likeRENDER_API_KEYand mandating that captured secrets never appear in logs or chat output. - [EXTERNAL_DOWNLOADS]: The skill mentions the
Asidebrowser (aside.com) as a recommended tool for handling third-party web actions. It performs a local probe to check for the tool's presence but does not attempt to download or install it automatically, relying instead on user-initiated setup.
Audit Metadata