qstack-serve-plans
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local commands to host project files, specifically utilizing a repository-based bash script (
qstack/scripts/serve.sh) or the standard Pythonhttp.servermodule.\n- [DATA_EXFILTRATION]: The skill facilitates network access to the contents of theqstack/compound_engineeringdirectory. Security is maintained through instructional guardrails that require user confirmation for the binding address and recommend the use of127.0.0.1for local-only access.
Audit Metadata