skills/time-attack/gstack/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently executes git commands, linters (Biome, ESLint, Ruff), and test runners (Jest, pytest) to evaluate the repository content and state as part of its core review workflow.- [EXTERNAL_DOWNLOADS]: The runtime-bootstrap.mjs script fetches a manifest and binary components from the official time-attack/gstack GitHub repository. This is an opt-in process for the optional runtime with built-in domain allowlisting to official vendor hosts.- [REMOTE_CODE_EXECUTION]: The bootstrap installer executes a downloaded install.js script to set up the runtime environment. Integrity is verified using SHA-256 and optional Cosign signatures to ensure the authenticity of the vendor-supplied code.- [DATA_EXFILTRATION]: The skill is designed to send code diffs and plans to external models (OpenAI Codex) and research services (Context.dev). It employs a comprehensive redaction engine to scrub credentials and PII before transmission, ensuring sensitive data does not leave the machine.- [DATA_EXFILTRATION]: The GBrain code intelligence feature can send repository content to a remote database to improve search capabilities, which requires explicit per-repository consent from the user before any data is indexed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 04:18 PM
Security Audit — agent-trust-hub — review