gsd-execute-phase

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied input via the $ARGUMENTS variable to determine phase numbers and execution flags. While this creates a potential surface for indirect prompt injection, it is a standard implementation for parameter-driven tasks.
  • Ingestion points: $ARGUMENTS variable in SKILL.md.
  • Boundary markers: None explicitly defined for the argument block.
  • Capability inventory: Access to Bash, Agent, Read, and Write tools.
  • Sanitization: No specific sanitization logic is visible in the prompt instructions.
  • [DATA_EXPOSURE]: The skill references specific files in the ~/.claude/gsd-core/ directory as part of its execution context. These paths appear to be internal configuration and reference files for the GSD workflow and are consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 09:38 PM
Security Audit — agent-trust-hub — gsd-execute-phase