Parallel Orchestrate

PassAudited by VirusTotal on May 13, 2026.

Findings (1)

The skill performs complex git orchestration and subagent management but includes high-risk behaviors, specifically the use of `eval` on the output of a local binary (`gstack-slug`) in SKILL.md (Phase 0.3), which presents a shell injection vulnerability. Additionally, it implements a telemetry system that writes session data to `~/.gstack/analytics/` and invokes an external binary (`gstack-telemetry-log`) for potential remote data exfiltration. While these features are documented as part of the 'gstack' ecosystem's performance tracking, the combination of insecure execution patterns and telemetry hooks meets the threshold for a suspicious classification.