Documentation
README
gstack-cso
Use this skill for a security review with OWASP and STRIDE lenses.
Scope
Prioritize OPC-specific attack surfaces:
- Electron main/preload/renderer IPC
- Local provider bridges and localhost auth
- API key and token storage
- Plugin, hook, skill, and MCP loading
- Shell command construction and tool permissions
- File reads/writes, path traversal, symlinks, and workspace boundaries
- Prompt injection from web, files, tool output, or plugin content
Workflow
This is the opening of the README. Read the full README on GitHub.