kw-gsd-help-flow
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The documentation references in
references/gsd-core.mdregarding 'human gates' and 'write-guard hooks' describe the safety and security features of the underlying GSD Core framework. These entries serve as informative guides on how the framework prevents autonomous action without consent, rather than being attempts to override agent constraints or hide malicious activity.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses an 'investigation' surface through its ability to readSKILL.mdfiles from other installed skills at~/.claude/skills/. While this involves ingesting external data, the skill instructions strictly define a read-only advisory role, directing the agent to recommend commands for user confirmation rather than executing them. This significantly mitigates the risk of instructions embedded in other skills being accidentally followed.\n- [SAFE]: The skill performs limited file system operations to read documentation and version metadata (e.g.,~/.claude/gsd-core/VERSION). This access is purposeful and constrained to the framework's own files, which is necessary to provide the user with version-accurate assistance.
Audit Metadata