skills/garrytan/gstack/sync-gbrain/Gen Agent Trust Hub

sync-gbrain

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill utilizes the eval command to execute the output of a local binary (gstack-slug), which is used to dynamically set environment variables for recovering project context during session startup.
  • [INDIRECT_PROMPT_INJECTION]: The skill indexes the entire repository's content into the gbrain search engine. This creates a vulnerability surface where potentially malicious instructions within the repository files could be retrieved and followed by the agent during future search operations.
  • Ingestion points: Repository files processed through gbrain sync and gbrain reindex-code in SKILL.md.
  • Boundary markers: Guidance is added to CLAUDE.md to help the agent distinguish between search tools, but there is no specific instruction to ignore malicious content within the search results.
  • Capability inventory: The skill has access to Bash, Read, Write, Edit, Glob, and Grep tools, which could be leveraged if an injection is successful.
  • Sanitization: No specific sanitization or filtering of the indexed repository content is documented.
  • [COMMAND_EXECUTION]: The skill frequently executes local binaries and scripts (e.g., gbrain, gstack-skill-start, gstack-config, gstack-gbrain-sync.ts) to manage configuration, probe engine status, and perform the synchronization logic.
  • [DATA_EXFILTRATION]: The skill records and logs telemetry data (such as session IDs, timestamps, and task outcomes) via the gstack-skill-end script at the conclusion of each run.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — sync-gbrain