gjc-sdk-author

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The templates execute the gjc CLI using subprocess calls. This is handled safely by passing arguments as an array rather than a shell string in templates/direct-sdk.py and templates/direct-sdk.ts, which prevents command injection vulnerabilities.
  • [DATA_EXFILTRATION]: The scripts include a redaction mechanism in templates/direct-sdk.py and templates/direct-sdk.ts that scans for common sensitive field names such as 'secret', 'token', and 'password', redacting their values before displaying output to the user.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes output from the gjc CLI and mitigates potential injection risks by parsing the output as JSON and redacting sensitive information before presenting it to the agent.
  • Ingestion points: CLI stdout is read into the script context in templates/direct-sdk.py and templates/direct-sdk.ts.
  • Boundary markers: The output is parsed as structured JSON in both templates, providing a clear boundary between external data and code logic.
  • Capability inventory: The scripts perform subprocess execution via subprocess.run in templates/direct-sdk.py and Bun.spawn in templates/direct-sdk.ts, restricted to the specified repository directory.
  • Sanitization: A redact function is implemented in both templates to filter out sensitive keys based on a regex allowlist before outputting results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:12 PM
Security Audit — agent-trust-hub — gjc-sdk-author