gsd-workstreams
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines a set of operations that invoke a local Node.js tool through the
$GSD_TOOLSenvironment variable. - [COMMAND_EXECUTION]: User-provided workstream names are passed as arguments to the CLI tool. While consistent with the skill's purpose, this pattern requires the execution environment to sanitize inputs to prevent command injection.
Audit Metadata