gsd-manager
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local workflow scripts such as
analyze-dependencies.mdandmanager.mdlocated within the vendor's~/.claude/gsd-core/directory. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests project-controlled data.
- Ingestion points: Reads
.planning/STATE.mdand.planning/ROADMAP.md(SKILL.md). - Boundary markers: Absent; the skill does not explicitly define delimiters for untrusted file content.
- Capability inventory: Accesses
Bash,Write,Skill, andAgenttools as listed in the frontmatter (SKILL.md). - Sanitization: No sanitization or filtering of the ingested planning files is specified.
Audit Metadata