gjc-sdk-author
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The templates execute the
gjcCLI using subprocess calls. This is handled safely by passing arguments as an array rather than a shell string intemplates/direct-sdk.pyandtemplates/direct-sdk.ts, which prevents command injection vulnerabilities. - [DATA_EXFILTRATION]: The scripts include a redaction mechanism in
templates/direct-sdk.pyandtemplates/direct-sdk.tsthat scans for common sensitive field names such as 'secret', 'token', and 'password', redacting their values before displaying output to the user. - [INDIRECT_PROMPT_INJECTION]: The skill processes output from the
gjcCLI and mitigates potential injection risks by parsing the output as JSON and redacting sensitive information before presenting it to the agent. - Ingestion points: CLI stdout is read into the script context in
templates/direct-sdk.pyandtemplates/direct-sdk.ts. - Boundary markers: The output is parsed as structured JSON in both templates, providing a clear boundary between external data and code logic.
- Capability inventory: The scripts perform subprocess execution via
subprocess.runintemplates/direct-sdk.pyandBun.spawnintemplates/direct-sdk.ts, restricted to the specified repository directory. - Sanitization: A
redactfunction is implemented in both templates to filter out sensitive keys based on a regex allowlist before outputting results.
Audit Metadata