gsd-stats
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data and workflow files which could potentially contain malicious instructions.
- Ingestion points: The skill reads from
~/.claude/gsd-core/workflows/stats.mdand standard project files (git metrics, plans, requirements). - Boundary markers: Absent. There are no instructions to the agent to delimit or ignore instructions embedded in the project data.
- Capability inventory: The skill is configured to use the
BashandReadtools. - Sanitization: Absent. The skill does not specify any validation or filtering of the ingested project metrics or workflow content.
Audit Metadata