skills/open-gsd/gsd-core/gsd-thread/Gen Agent Trust Hub

gsd-thread

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates external context from a local file into the agent's execution environment. If the content of the thread storage is influenced by untrusted external data, it could lead to the agent executing unintended commands during subsequent sessions.
  • Ingestion points: The execution_context field references ~/.claude/gsd-core/workflows/thread.md (SKILL.md).
  • Boundary markers: No delimiters or safety instructions are defined to separate the loaded thread context from system instructions.
  • Capability inventory: The skill has access to Bash, Read, and Write tools (SKILL.md).
  • Sanitization: There is no evidence of validation or sanitization of the content loaded from the thread storage.
  • [COMMAND_EXECUTION]: The skill is granted Bash tool permissions, which can be combined with loaded context to perform system operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 12:43 AM
Security Audit — agent-trust-hub — gsd-thread