gstack-review - Infrastructure-first security audit
Audits infrastructure, code, dependencies, CI/CD, AI systems, and agent-skill supply chains for security findings.
Tags
Updated: 2026-10-08Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Detect technology stacks
- Map attack surfaces
- Find leaked secrets
- Audit dependency supply chains
- Review CI/CD security
- Inspect infrastructure configurations
- Audit webhooks and integrations
- Assess LLM security
- Review agent-skill supply chains
- Apply OWASP and STRIDE
- Verify findings actively
- Produce security posture reports
Inputs
- Project repository
- Git history
- Configuration files
- User-selected audit mode
- Audit scope
- Current branch changes
Outputs
- Security posture report
- Attack surface map
- Severity-rated findings
- Remediation plans
- Skipped-check notes
Requirements
- Shell access
- File read access
- Grep search tools
- Git repository access for history checks
