qstack-serve-plans

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill initiates background processes using bash or python3 with user-defined parameters for the network port and bind address.
  • [DATA_EXFILTRATION]: The skill sets up a web server that hosts files from the qstack/compound_engineering directory, potentially exposing them to the network if a non-local bind address is selected.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and serves repository-based HTML files, creating a surface for potential instruction injection.
  • Ingestion points: Files in qstack/compound_engineering/ (SKILL.md).
  • Boundary markers: Absent.
  • Capability inventory: Subprocess execution for git, bash, and python3, and network service creation (SKILL.md).
  • Sanitization: None for served file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:27 AM