skills/garrytan/gstack/ship/Gen Agent Trust Hub

ship

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from multiple sources, including plan files (Step 8), PR descriptions (Step 8.2), and external review comments from Greptile (Step 10). This data is used to drive agent actions, creating a surface for potential indirect prompt injection attacks.
  • Ingestion points: Plan files (Step 8, sections/plan-completion.md), PR bodies (Step 8.2), and Greptile comments (Step 10).
  • Boundary markers: The skill implements strict SESSION_ID verification for tool results and uses gstack-issue-guard to treat PR envelope content as data rather than instructions.
  • Capability inventory: The skill utilizes Bash, Write, Edit, Glob, and Agent (for subagent dispatch).
  • Sanitization: It employs gstack-redact for outgoing PR content and gstack-issue-guard to wrap incoming untrusted text.
  • [DYNAMIC_EXECUTION]: The workflow performs several types of dynamic code execution to automate development tasks. This includes using eval to load environment variables from the output of the local gstack-slug binary, using source <(command) for dynamic context recovery, and generating new test files based on AI analysis of coverage gaps (Step 7), which are then executed by the project's test runner. It also utilizes aside repl for browser automation and codex exec for external code review processing.
  • [EXTERNAL_DOWNLOADS]: The skill automatically installs necessary third-party utilities when missing, such as fastlane via Homebrew for Apple platform releases and @openai/codex via npm for code reviews. These downloads originate from well-known and trusted technology organizations.
  • [COMMAND_EXECUTION]: The skill frequently executes shell commands to interact with git, package managers, and local development servers. It includes a network probe that uses curl to check common ports on localhost to detect active development servers, which is a whitelisted operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — ship