skills/open-gsd/gsd-core/gsd-phase/Gen Agent Trust Hub

gsd-phase

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill's behavior matches its described purpose of roadmap management.\n- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute local workflow templates stored in the user's home directory (~/.claude/gsd-core/workflows/). These are vendor-provided resources associated with the skill author 'open-gsd'.\n- [PROMPT_INJECTION]: The skill processes user input via the $ARGUMENTS variable. Evidence: 1. Ingestion points: $ARGUMENTS in SKILL.md; 2. Boundary markers: Absent; 3. Capability inventory: Bash and Write tools; 4. Sanitization: Not explicitly handled in the routing logic. This represents an indirect prompt injection surface where the integrity of the roadmap depends on the sub-workflows correctly handling the passed strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 09:38 PM
Security Audit — agent-trust-hub — gsd-phase