gsd-discuss-phase

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bash block to locate a local shim script (gsd-tools.cjs) and execute it using Node.js to retrieve configuration values.
  • [COMMAND_EXECUTION]: The process dynamically loads and executes instructions from markdown files located in the ~/.claude/gsd-core/workflows/ directory based on the execution mode and user arguments.
  • [EXTERNAL_DOWNLOADS]: If local tools are not found, the skill provides a command to download and install the @opengsd/gsd-core package from npm using npx. This package is a vendor-owned resource associated with the author 'open-gsd'.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 09:38 PM
Security Audit — agent-trust-hub — gsd-discuss-phase