qstack-plan-close
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard shell commands including
ls,git log, andgrepto inspect the local project structure and commit history. These operations are scoped to local discovery and documenting project status. - [DYNAMIC_EXECUTION]: The agent is instructed to run
node --checkon a local JavaScript file (board-events.js) to validate its syntax. While the--checkflag prevents full code execution, this pattern involves invoking a language runtime on local script files. - [INDIRECT_PROMPT_INJECTION]: The skill processes and summarizes data from various local project files such as
plan.html,execution.md, andboard-events.js. This ingestion of untrusted data into the agent's context creates a surface for indirect prompt injection. - Ingestion points: Reads files from the
qstack/compound_engineering/plans/directory and its legacy counterparts. - Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the interpolation of project file contents into the generated outcome report.
- Capability inventory: Limited to local file system queries (
ls,grep), git history inspection, syntax validation (node --check), and markdown file generation. - Sanitization: No explicit validation or filtering logic is specified for the data ingested from project files.
Audit Metadata