skills/hani-q/qstack/qstack-next/Gen Agent Trust Hub

qstack-next

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions require the agent to execute shell commands to determine the current state of the workspace. These include Git operations (git branch, git status, git log) and directory listings (ls) of skill installation paths like ~/.claude/skills, ~/.codex/skills, and ~/.agents/skills.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from the local filesystem and conversation history to determine its recommendations. Ingestion points: plan.md, plan.html, board-events.js, execution.md, and outcome.md within the qstack/compound_engineering/plans/ or compound-engineering/plans/ directories. Boundary markers: The skill does not define specific boundary markers for the data it reads, though it includes a directive to 'read what you need and no more' and maintain a 'read-only' status. Capability inventory: Shell commands (git, ls) for environment inspection. Sanitization: No explicit logic for sanitizing or escaping content from the plan files is provided before the data influences the agent's recommendation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:27 AM