aidlc-scope

Warn

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bash command engine orchestrate next --scope $ARGUMENTS using the {{INVOKE}} directive. This invokes a local binary or script named engine with arguments provided at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill serves as a surface for injection by interpolating untrusted input into a sensitive execution context.
  • Ingestion points: User-supplied input via the $ARGUMENTS variable in SKILL.md.
  • Boundary markers: None. The skill does not use delimiters or provide instructions to the agent to ignore potentially malicious embedded content.
  • Capability inventory: Execution of shell commands via bash as defined in the skill's logic.
  • Sanitization: None. The instructions explicitly state to "pass every argument through verbatim," which bypasses standard shell escaping and allows for command injection if metacharacters like ;, &, or | are included in the input.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 4, 2026, 07:24 PM
Security Audit — agent-trust-hub — aidlc-scope