aidlc-scope
Warn
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a bash command
engine orchestrate next --scope $ARGUMENTSusing the{{INVOKE}}directive. This invokes a local binary or script namedenginewith arguments provided at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill serves as a surface for injection by interpolating untrusted input into a sensitive execution context.
- Ingestion points: User-supplied input via the
$ARGUMENTSvariable inSKILL.md. - Boundary markers: None. The skill does not use delimiters or provide instructions to the agent to ignore potentially malicious embedded content.
- Capability inventory: Execution of shell commands via
bashas defined in the skill's logic. - Sanitization: None. The instructions explicitly state to "pass every argument through verbatim," which bypasses standard shell escaping and allows for command injection if metacharacters like
;,&, or|are included in the input.
Audit Metadata