stacktree-sideshow-handoff

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill's primary function is to collect data from a local server (defaulting to http://localhost:8228) and transmit it to an external service at stacktr.ee. The content sent may include internal hostnames, terminal logs, and code diffs. While the skill mandates a --pii-check block flag to mitigate risk, the transmission of local environment data to a remote server is a core behavior.
  • [COMMAND_EXECUTION]: The instructions direct the agent to execute a local shell script (bash scripts/publish.sh) to perform the data upload, which is a standard but sensitive operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data gathered during agent iteration (HTML, Markdown, terminal output) and renders it into a self-contained document for external delivery.
  • Ingestion points: Data is fetched from a running sideshow server at localhost:8228 or reconstructed from previous conversation context.
  • Boundary markers: None identified; the skill instructs the agent to "recompose" parts into a single document without explicit delimiters to prevent the agent from obeying instructions embedded in the processed data.
  • Capability inventory: The skill uses bash scripts/publish.sh and the publish_html tool, providing both shell execution and network access.
  • Sanitization: The skill utilizes a --pii-check block flag during the publishing step to filter sensitive identifiers before exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:58 AM