gsd-secure-phase

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill references workflow configuration stored in ~/.claude/gsd-core/workflows/. This path is used for the GSD (Get Stuff Done) framework's own workflow definitions and does not represent an unauthorized access to sensitive user credentials.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform its auditing and verification tasks. This is standard for development-focused skills that need to interact with the file system and project artifacts.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files like SECURITY.md and PLAN.md. While these are external inputs, the risk is inherent to the auditing process, and the skill is designed to process these files to generate security reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 09:38 PM
Security Audit — agent-trust-hub — gsd-secure-phase