Atlas / Skills / gentleman-programming / gentle-shell

gentle-shellBLOCK

skills/gentleman-programming/gentle-shell

Gentle Shell is a Pi-native coding-agent harness for controlled development with Organic Driven Development, optional SDD/OpenSpec, subagents, TDD evidence, review guardrails, skills, and memory integrations.

Verdict
BLOCK
Grade
D
Trust score
67 /100
Version
1.0
Hosts
6 documented
License
MIT
Stars
1,143
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

gentle-shellTM

Your coding agent for controlled development in the workspace you lead.

Website · Quickstart · Docs · Wiki

Your terminal can run an agent. Your workspace should help you lead it.gentle-shell is your coding agent, bringing your changes, tasks, and engineering workflow together—built for Pi.

One workspace. A coding agent you direct. A workflow you can inspect.

🎬 See it in action

Read from source at commit 134d1045788dOBSERVED · 2026-09-30
02

Install

Commands as the repository documents them. They are shown, not run.

npm i -g gentle-pi
npm i -g gentle-pi
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
cursormentioned
openclawmentioned
windsurfmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: gentle-ai-branch-pr
description: "Create Gentle AI pull requests with issue-first checks. Trigger: creating, opening, or preparing PRs for review."
license: Apache-2.0
metadata:
  author: gentleman-programming
  version: "2.0"
---

## When to Use

Use this skill when:
- Creating a pull request for any change
- Preparing a branch for submission
- Helping a contributor open a PR

---

## Critical Rules

1. **Every PR MUST link an approved issue** — no exceptions
2. **Every PR MUST have exactly one `type:*` label**
3. **REQUIRED CI must pass according to target policy** before merge; CodeRabbit is optional unless required by that policy
4. **Blank PRs without issue linkage will be blocked** by GitHub Actions

---

## Target and Authorization

- Inspect `origin` locally (`git remote get-url origin`) and establish one unambiguous target host and `owner/repo`. Do not infer the target from the cwd or assume `main`. Stop if ambiguous.
- Obtain explicit remote destination, operation and credential/session authorization before any target-host reads, including `gh auth status` or repository metadata. Do not inspect or reuse an ambient SSH agent. Permission for a read does not authorize a write; confirm each remote operation is within the grant.
- Once authorized, reuse fresh target-bound issue, default branch, type labels and checks evidence from this session instead of repeating discovery. Refresh stale or mismatched evidence; do not substitute another host's data. Resolve the base from the authorized target's default branch or a human-selected base.
- Do not automatically commit, push, open a PR or merge. Prepare and report a candidate; perform each action only with its own authorization. Local preparation is not permission for remote delivery.

## Workflow

1. Identify the authorized target and verify that the linked issue is approved; choose with the human whether the reference closes it or is nonclosing.
2. Select the base from target metadata and prepare a `type/description` branch only when requested.
3. Implement in work units with conventional commits when authorized; follow the merged ODD applicable test-first policy, run applicable tests, shellcheck on modified scripts, and test changed skills in at least one agent when relevant. The per-task advisory 400 authored-line heuristic is not an automatic split or a reason to omit tests or docs.
4. Prepare the PR body from the target template and evidence. On separate authorization, open the PR and add exactly one `type:*` label.
5. Check target-policy required CI and report pending/failing checks rather than declaring merge-ready.

---

## Branch Naming

Branch names MUST match this regex:

```
^(feat|fix|chore|docs|style|refactor|perf|test|build|ci|revert)\/[a-z0-9._-]+$
```

**Format:** `type/description` — lowercase, no spaces, only `a-z0-9._-` in description.

| Type | Branch pattern | Example |
|------|---------------|---------|
| Feature | `feat/<description>` | `feat/user-login` |
| Bug fix | `fix/<description>` | `fix/zsh-glob-error` |
| Chore | `chore/<description>` | `chore/update-ci-actions` |
| Docs | `docs/<description>` | `docs/installation-guide` |
| Style | `style/<description>` | `style/format-scripts` |
| Refactor | `refactor/<description>` | `refactor/extract-shared-logic` |
| Performance | `perf/<description>` | `perf/reduce-startup-time` |
| Test | `test/<description>` | `test/add-setup-coverage` |
| Build | `build/<description>` | `build/update-shellcheck` |
| CI | `ci/<description>` | `ci/add-branch-validation` |
| Revert | `revert/<description>` | `revert/broken-setup-change` |

---

## PR Body Format

Use the authorized target's `.github/PULL_REQUEST_TEMPLATE.md`. Fill it from observed evidence, retaining its required sections.

### 1. Linked Issue (REQUIRED)

Use the human-selected closing (`Closes #N`, `Fixes #N`, or `Resolves #N`) or nonclosing `Refs #N` reference. Do not turn `Refs` into an automatic close. The linked issue MUST have the `status:approved` label; reuse fresh target-bound verification.

### 2. PR Type (REQUIRED)

Check exactly ONE in the template and add the matching label:

| Checkbox | Label to add |
|----------|-------------|
| Bug fix | `type:bug` |
| New feature | `type:feature` |
| Documentation only | `type:docs` |
| Code refactoring | `type:refactor` |
| Maintenance/tooling | `type:chore` |
| Breaking change | `type:breaking-change` |

### 3. Summary

1-3 bullet points of what the PR does.

### 4. Changes Table

```markdown
| File | Change |
|------|--------|
| `path/to/file` | What changed |
```

### 5. Test Plan

Record actual commands and outcomes, including shellcheck on modified scripts, manual testing of affected functionality, and whether changed skills load in at least one agent. Mark inapplicable checks as such; do not invent successful runs.

### 6. Contributor Checklist

Do not mark an unverified `[x]` checkbox. Check each item only after evidence supports it; leave pending items unchecked, including approved issue, exactly one `type:*` label, applicable shellcheck, skills tested in at least one agent, docs updated if behavior changed, conventional commit format, and no `Co-Authored-By` trailers. If a template demands every box checked, resolve outstanding items before submission rather than falsely attesting.

---

## Labels and Automated Checks

- Apply exactly one `type:*` label from the authorized target's available labels. A commit-type mapping below is a suggestion, not proof of label availability or permission.
- Protected labels require an exact direct instruction naming the label and an actor with MAINTAIN/ADMIN permission. Do not infer authorization from a general request to prepare or open a PR.
- For a PR above the advisory 400 authored-line review budget, record the human-selected `size:exception` rationale if that route was selected; no separate instructor proof is required. Apply the protected label only under the same direct-instruction and actor rule. Do 
05

Trust audit

BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (1 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
lib/runtime-metrics-policy.ts:35
const result = await exec({ file: resolve(), arguments: ["telemetry", "policy", "--json"],
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/review-candidate-view.test.ts:513
const secret = "private-fixture-path-and-user";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/review-candidate-view.test.ts:606
if (lists === 2) writeFileSync(marker, JSON.stringify({ ...owner, token: "00000000-0000-4000-8000-000000000000" }));
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/review-candidate-view.test.ts:693
writeFileSync(marker, JSON.stringify({ ...JSON.parse(bytes), token: "00000000-0000-4000-8000-000000000000" }));
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/review-agent-end-preflight.test.ts:153
return exec(file, args, options);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
extensions/skill-registry.ts:257
contentHash = createHash("sha1").update(await readFile(file)).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
extensions/skill-registry.ts:268
return createHash("sha1").update(lines.join("\n")).digest("hex");
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/runtime-harness.mjs:718
const sensitiveEdit = await toolHook({ toolName: "edit", input: { edits: [], path: join(toolCwd, "id_rsa.pem") } }, createCtx(toolCwd));
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
extensions/history/index.ts:40
import { gentlePiConfigHome } from "../../lib/agent-home.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
extensions/history/index.ts:45
} from "../../lib/history-capture-policy.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/maintainer/provider-relay-matrix.mjs:17
import { REVIEW_HOST_RELAY_FAILURE, ReviewHostRelayError, classifyReviewHostRelayRefusal, resolveReviewHostRelaySubmission, runReviewHostRelaySlot } from "../../lib/review-host-relay.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/maintainer/provider-relay-matrix.mjs:18
import { GENTLE_PI_REVIEW_RELAY_CONTRACT, GENTLE_PI_REVIEW_RELAY_CONTRACT_ENV } from "../../lib/review-relay-contract.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/crosslane/cross-lane.mjs:5
import { decodeReviewLastEventClosureV1 } from "../../runtime/review-integration-v2.mjs";
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/gentle-shell.test.ts:858
for (const key of ["é", " ", "👩💻"]) editor.handleInput(key);
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/gentle-shell.test.ts:860
assert.equal(editor.getText(), "é 👩💻one two three");
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/gentle-shell.test.ts:870
editor.handleInput("c"); editor.handleInput("w"); editor.handleInput("👩💻"); editor.handleInput("é"); editor.handleInput("\x1b");
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/gentle-shell.test.ts:871
assert.equal(editor.getText(), "👩💻étwo three");
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/gentle-shell.test.ts:873
assert.equal(editor.getText(), "👩💻étwo 👩💻é");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
odd/tasks/inprocess-reviewer-provider-resolution.md:121
because the module's *own* contract (never invent an `apiKey`, never read `process.env`) is worth
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
odd/tasks/inprocess-reviewer-provider-resolution.md:310
resolvers already read `process.env` through the auth context and `getApiKeyAndHeaders` runs before
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/chained-pr/references/chaining-details.md:90
Before any remote read or PR creation, require explicit human authorization for the destination (exact host/repository), operation (PR read or creation), and credential/session. Do not probe credentia
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/gentle-shell.md:121
- For NaN Cloud, usage comes from the quota endpoint the official dashboard reads, with the same API key pi already holds. Each metered model reports one allowance for the billing period, and that win
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/gentle-shell.md:184
- `orchestrator_session_id`, `orchestrator_list`, and `orchestrator_send_message` provide local-profile session notifications. List results advertise IDs only and reachability remains unknown. Sending
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
assets/gentle-logo-only.png
assets/gentle-logo-only.png
Why it matters. 1178688 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 134d1045788dfull audit observations/trust-audit/skill/gentleman-programming__gentle-shell.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-30134d1045788dBLOCKD67first audit
07

Questions

What does the gentle-shell skill do?

Gentle Shell is a Pi-native coding-agent harness for controlled development with Organic Driven Development, optional SDD/OpenSpec, subagents, TDD evidence, review guardrails, skills, and memory integrations.

Is gentle-shell safe to install?

No — not without reading the findings first. The audit graded it D (67/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can gentle-shell access on my machine?

The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.

Which assistants does gentle-shell work with?

Its documentation mentions claude-code, codex, copilot, cursor, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (134d1045788d), read on 2026-09-30. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement