sync-gbrain
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill utilizes the
evalcommand to execute the output of a local binary (gstack-slug), which is used to dynamically set environment variables for recovering project context during session startup. - [INDIRECT_PROMPT_INJECTION]: The skill indexes the entire repository's content into the
gbrainsearch engine. This creates a vulnerability surface where potentially malicious instructions within the repository files could be retrieved and followed by the agent during future search operations. - Ingestion points: Repository files processed through
gbrain syncandgbrain reindex-codeinSKILL.md. - Boundary markers: Guidance is added to
CLAUDE.mdto help the agent distinguish between search tools, but there is no specific instruction to ignore malicious content within the search results. - Capability inventory: The skill has access to
Bash,Read,Write,Edit,Glob, andGreptools, which could be leveraged if an injection is successful. - Sanitization: No specific sanitization or filtering of the indexed repository content is documented.
- [COMMAND_EXECUTION]: The skill frequently executes local binaries and scripts (e.g.,
gbrain,gstack-skill-start,gstack-config,gstack-gbrain-sync.ts) to manage configuration, probe engine status, and perform the synchronization logic. - [DATA_EXFILTRATION]: The skill records and logs telemetry data (such as session IDs, timestamps, and task outcomes) via the
gstack-skill-endscript at the conclusion of each run.
Audit Metadata