plan-ceo-review
Pass
Audited by Gen Agent Trust Hub on May 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
Bashtool to perform system audits, verify git history, and manage local session state. It also employsevalandsourceon the output of local binaries in the~/.claude/skills/gstack/bin/directory to configure its runtime environment. - [DATA_EXFILTRATION]: The skill includes optional features for telemetry and session synchronization ('GBrain Sync') that send usage data and session memory to external services. These features are gated by explicit user consent prompts, ensuring that no data is exfiltrated without the user's knowledge.
- [EXTERNAL_DOWNLOADS]: The skill utilizes
WebSearchandcodex exec(an external tool) to fetch market landscape information and perform adversarial plan reviews. These tools are used to provide broader context and independent verification of the developer's plans.
Audit Metadata