skills/time-attack/gstack/ship/Gen Agent Trust Hub

ship

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches optional runtime components and signed manifest metadata from the official GStack GitHub repository.
  • [EXTERNAL_DOWNLOADS]: Installs well-known distribution tools such as fastlane via Homebrew as part of the App Store release journey.
  • [REMOTE_CODE_EXECUTION]: Executes a verified runtime installer script from a downloaded archive after performing SHA-256 and Cosign integrity checks.
  • [COMMAND_EXECUTION]: Orchestrates the release lifecycle through standard CLI tools including git, GitHub CLI (gh), GitLab CLI (glab), and platform-specific deployment binaries.
  • [DATA_EXFILTRATION]: Interacts with established cloud services (GitHub, GitLab, Apple App Store Connect) using official APIs for pull requests, build uploads, and app management.
  • [CREDENTIALS_UNSAFE]: Manages sensitive session tokens and API keys for store distribution by storing them in local files with restricted permissions (0600) and using redaction logic to keep them out of logs and transcripts.
  • [SAFE]: Implements a strict authority policy that treats repository content and tool output as untrusted, preventing data-driven prompt injection from escalating capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 04:18 PM
Security Audit — agent-trust-hub — ship