gsd-validate-phase
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to audit artifacts and manage validation files, which is appropriate for its stated purpose of filling documentation gaps.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill references a local workflow file at~/.claude/gsd-core/workflows/validate-phase.md. This path resides in the user's home directory and corresponds to the framework used for orchestrating the validation process.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project artifacts, creating a potential surface for indirect prompt injection.\n - Ingestion points: Reads files and artifacts using the
Read,Glob, andGreptools.\n - Boundary markers: None explicitly defined in the instruction set.\n
- Capability inventory: Includes powerful tools such as
Bash,Write, andEdit.\n - Sanitization: No specific sanitization or filtering logic is present in the skill's instructions.
Audit Metadata