ship
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from multiple sources, including plan files (Step 8), PR descriptions (Step 8.2), and external review comments from Greptile (Step 10). This data is used to drive agent actions, creating a surface for potential indirect prompt injection attacks.
- Ingestion points: Plan files (Step 8, sections/plan-completion.md), PR bodies (Step 8.2), and Greptile comments (Step 10).
- Boundary markers: The skill implements strict
SESSION_IDverification for tool results and usesgstack-issue-guardto treat PR envelope content as data rather than instructions. - Capability inventory: The skill utilizes
Bash,Write,Edit,Glob, andAgent(for subagent dispatch). - Sanitization: It employs
gstack-redactfor outgoing PR content andgstack-issue-guardto wrap incoming untrusted text. - [DYNAMIC_EXECUTION]: The workflow performs several types of dynamic code execution to automate development tasks. This includes using
evalto load environment variables from the output of the localgstack-slugbinary, usingsource <(command)for dynamic context recovery, and generating new test files based on AI analysis of coverage gaps (Step 7), which are then executed by the project's test runner. It also utilizesaside replfor browser automation andcodex execfor external code review processing. - [EXTERNAL_DOWNLOADS]: The skill automatically installs necessary third-party utilities when missing, such as
fastlanevia Homebrew for Apple platform releases and@openai/codexvia npm for code reviews. These downloads originate from well-known and trusted technology organizations. - [COMMAND_EXECUTION]: The skill frequently executes shell commands to interact with git, package managers, and local development servers. It includes a network probe that uses
curlto check common ports onlocalhostto detect active development servers, which is a whitelisted operation.
Audit Metadata