Back to skill

Security audit

GSD Agent (→ gsd-orchestrator)

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a transparent placeholder skill that redirects users to a separate GSD orchestrator skill, with no hidden code or autonomous behavior in the artifact.

Installing this placeholder appears low risk, but it is not the functional orchestrator. Before following the redirect, review gsd-orchestrator and the gsd-pi package because those separate components may request their own permissions or run their own code.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.