skills/open-gsd/gsd-core/gsd-health/Gen Agent Trust Hub

gsd-health

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the gsd-tools CLI utility via the Bash tool to perform health checks and context validation, which is an expected behavior for this vendor's ecosystem.
  • [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by reading content from the .planning/ directory to validate integrity.
  • Ingestion points: Data is ingested from all files within the local .planning/ directory.
  • Boundary markers: No delimiters or ignore instructions are used to separate scanned data from the agent's internal reasoning.
  • Capability inventory: The skill is permitted to use Read, Write, and Bash tools, which allow for file system changes and command execution.
  • Sanitization: There is no evidence of content sanitization or validation of the files read from the local directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 09:38 PM
Security Audit — agent-trust-hub — gsd-health