gsd-health
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the gsd-tools CLI utility via the Bash tool to perform health checks and context validation, which is an expected behavior for this vendor's ecosystem.
- [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by reading content from the .planning/ directory to validate integrity.
- Ingestion points: Data is ingested from all files within the local .planning/ directory.
- Boundary markers: No delimiters or ignore instructions are used to separate scanned data from the agent's internal reasoning.
- Capability inventory: The skill is permitted to use Read, Write, and Bash tools, which allow for file system changes and command execution.
- Sanitization: There is no evidence of content sanitization or validation of the files read from the local directory.
Audit Metadata