skills/garrytan/gstack/skillify/Gen Agent Trust Hub

skillify

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill dynamically generates TypeScript code (script.ts and script.test.ts) based on the outcome of a successful /scrape operation. This synthesized code is executed locally via the 'bun' runtime to ensure the scraping logic remains valid before being committed to disk. This behavior is the primary intended function of the skill.\n- [COMMAND_EXECUTION]: The skill executes various local shell commands for session initialization, telemetry, and project metadata recovery. These commands interact with platform-specific binaries located in the user's home directory (~/.claude/skills/gstack/bin/), which are managed by the skill's author ('garrytan').\n- [INDIRECT_PROMPT_INJECTION]: Because the skill processes data from external websites, it implements guardrails to prevent indirect prompt injection. It explicitly instructs the agent to treat all strings extracted during the scraping process as untrusted and to disregard any instructions found within the page content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — skillify