qstack-serve-plans
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill initiates background processes using
bashorpython3with user-defined parameters for the network port and bind address. - [DATA_EXFILTRATION]: The skill sets up a web server that hosts files from the
qstack/compound_engineeringdirectory, potentially exposing them to the network if a non-local bind address is selected. - [INDIRECT_PROMPT_INJECTION]: The skill processes and serves repository-based HTML files, creating a surface for potential instruction injection.
- Ingestion points: Files in
qstack/compound_engineering/(SKILL.md). - Boundary markers: Absent.
- Capability inventory: Subprocess execution for
git,bash, andpython3, and network service creation (SKILL.md). - Sanitization: None for served file content.
Audit Metadata