gsd-validate-phase

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to audit artifacts and manage validation files, which is appropriate for its stated purpose of filling documentation gaps.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill references a local workflow file at ~/.claude/gsd-core/workflows/validate-phase.md. This path resides in the user's home directory and corresponds to the framework used for orchestrating the validation process.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project artifacts, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Reads files and artifacts using the Read, Glob, and Grep tools.\n
  • Boundary markers: None explicitly defined in the instruction set.\n
  • Capability inventory: Includes powerful tools such as Bash, Write, and Edit.\n
  • Sanitization: No specific sanitization or filtering logic is present in the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 09:38 PM
Security Audit — agent-trust-hub — gsd-validate-phase