qstack-serve-plans

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local commands to host project files, specifically utilizing a repository-based bash script (qstack/scripts/serve.sh) or the standard Python http.server module.\n- [DATA_EXFILTRATION]: The skill facilitates network access to the contents of the qstack/compound_engineering directory. Security is maintained through instructional guardrails that require user confirmation for the binding address and recommend the use of 127.0.0.1 for local-only access.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 11:57 AM
Security Audit — agent-trust-hub — qstack-serve-plans