aidlc-jump
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
engine orchestrate nextcommand locally to advance the active workflow. This operation is limited to the functionality of the existing orchestrator tool.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of user-provided arguments into a shell command, which is a common attack surface for indirect injection. - Ingestion points: User-provided inputs passed through the
$ARGUMENTSvariable inSKILL.md. - Boundary markers: None identified.
- Capability inventory: Execution of system commands via the
engineCLI. - Sanitization: The skill requires strict validation of input flags (
--stageor--phase) before invoking the engine, effectively filtering non-compliant input.
Audit Metadata