skills/open-gsd/gsd-core/gsd-manager/Gen Agent Trust Hub

gsd-manager

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local workflow scripts such as analyze-dependencies.md and manager.md located within the vendor's ~/.claude/gsd-core/ directory.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests project-controlled data.
  • Ingestion points: Reads .planning/STATE.md and .planning/ROADMAP.md (SKILL.md).
  • Boundary markers: Absent; the skill does not explicitly define delimiters for untrusted file content.
  • Capability inventory: Accesses Bash, Write, Skill, and Agent tools as listed in the frontmatter (SKILL.md).
  • Sanitization: No sanitization or filtering of the ingested planning files is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 09:38 PM
Security Audit — agent-trust-hub — gsd-manager