qstack-plan-close

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard shell commands including ls, git log, and grep to inspect the local project structure and commit history. These operations are scoped to local discovery and documenting project status.
  • [DYNAMIC_EXECUTION]: The agent is instructed to run node --check on a local JavaScript file (board-events.js) to validate its syntax. While the --check flag prevents full code execution, this pattern involves invoking a language runtime on local script files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and summarizes data from various local project files such as plan.html, execution.md, and board-events.js. This ingestion of untrusted data into the agent's context creates a surface for indirect prompt injection.
  • Ingestion points: Reads files from the qstack/compound_engineering/plans/ directory and its legacy counterparts.
  • Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the interpolation of project file contents into the generated outcome report.
  • Capability inventory: Limited to local file system queries (ls, grep), git history inspection, syntax validation (node --check), and markdown file generation.
  • Sanitization: No explicit validation or filtering logic is specified for the data ingested from project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:27 AM