test-audit
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill frequently executes local binaries located in the
~/.claude/skills/gstack/bin/directory, includinggstack-skill-start,gstack-slug,gstack-paths,gstack-decision-search, andgstack-skill-end. These commands are used for session management, path resolution, logging, and telemetry. - [DYNAMIC_EXECUTION]: The skill uses the
evalcommand to execute shell output produced by other binaries (e.g.,eval "$(~/.claude/skills/gstack/bin/gstack-slug ...)"). This allows the execution of dynamically generated code strings at runtime. - [DYNAMIC_EXECUTION]: The skill is designed to ingest and follow instructions dynamically provided by external tools via
GSTACK_INSTRUCTION_BEGINblocks. This mechanism allows the framework to inject new directives into the agent's context after the skill has already been loaded. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files (
SEED_PLAN) and dynamically injected instruction blocks, which serves as a potential vector for indirect prompt injection. - Ingestion points: Reads instruction blocks from the output of
gstack-skill-startand test plans from file paths determined during the discovery step. - Boundary markers: Uses specific delimiters (
GSTACK_INSTRUCTION_BEGIN/GSTACK_INSTRUCTION_END) and requires a matchingSESSION_IDgenerated at the start of the session to validate instruction blocks. - Capability inventory: The skill has access to powerful tools including
Bash,Write,Edit,Read, andGrep, enabling significant file system and shell operations. - Sanitization: Instructions mandate that the agent must only honor blocks that appear in direct tool results and carry a matching
SESSION_ID, ignoring any similar patterns found in general file or page content.
Audit Metadata