doubt-driven-development
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions and examples for executing external command-line tools to perform cross-model reviews. It specifically mentions tools like the Gemini CLI and Codex CLI.- [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary "artifacts" (such as code or text) and passes them to other AI models for review, creating a surface where malicious instructions embedded in an artifact could influence the reviewer's behavior.
- Ingestion points: User-provided artifacts and contracts processed during the Step 2 (EXTRACT) and Step 3 (DOUBT) phases.
- Boundary markers: The skill advises passing only the ARTIFACT and CONTRACT to the reviewer to minimize context leakage and suggests a hard mental separator in degraded self-questioning fallback scenarios.
- Capability inventory: Shell execution capabilities using external command-line tools.
- Sanitization: Instructions recommend using temporary files and stdin redirection to prevent shell injection from content within the artifacts.- [PROMPT_INJECTION]: The skill includes instructions intended to override the default behavior of sub-agents or personas, directing them to adopt an exclusively adversarial posture.
- Evidence: The skill explicitly states that the adversarial prompt takes precedence over the persona's default response shape and provides a template instructing the reviewer to assume the author is overconfident and to skip validation or summarization.
Audit Metadata