stacktree-sideshow-handoff
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill's primary function is to collect data from a local server (defaulting to
http://localhost:8228) and transmit it to an external service atstacktr.ee. The content sent may include internal hostnames, terminal logs, and code diffs. While the skill mandates a--pii-check blockflag to mitigate risk, the transmission of local environment data to a remote server is a core behavior. - [COMMAND_EXECUTION]: The instructions direct the agent to execute a local shell script (
bash scripts/publish.sh) to perform the data upload, which is a standard but sensitive operation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data gathered during agent iteration (HTML, Markdown, terminal output) and renders it into a self-contained document for external delivery.
- Ingestion points: Data is fetched from a running sideshow server at
localhost:8228or reconstructed from previous conversation context. - Boundary markers: None identified; the skill instructs the agent to "recompose" parts into a single document without explicit delimiters to prevent the agent from obeying instructions embedded in the processed data.
- Capability inventory: The skill uses
bash scripts/publish.shand thepublish_htmltool, providing both shell execution and network access. - Sanitization: The skill utilizes a
--pii-check blockflag during the publishing step to filter sensitive identifiers before exfiltration.
Audit Metadata