aidlc-context
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses and reads project files including source code, READMEs, and configuration files to identify technology stacks and patterns. This grants the agent broad access to the project's intellectual property and logical structure.
- [PROMPT_INJECTION]: The skill implements persistent instruction injection and is vulnerable to indirect prompt injection.
- Instruction Persistence: Generates platform-specific shims (
CLAUDE.md,.kiro/steering/aidlc.md) containing 'Behavioral Anchors' that override default agent behavior throughout the project lifecycle. - Indirect Injection Surface: Ingests workspace data such as source code and READMEs (
actions/assess.md) without sanitization or boundary markers in the resulting artifacts (context.md,blueprint-product.md). - Ingestion points: Filesystem scan of project files.
- Boundary markers: Absent.
- Capability inventory: File system write access and influence over downstream workflow phases.
- Sanitization: No escaping or validation of extracted content.
Audit Metadata