production-grade
Warn
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: Extensive use of dynamic context injection (the
!commandsyntax) inSKILL.mdto silently execute shell commands and read project-specific files at skill load time. - Evidence:
!git status,!cat CLAUDE.md, and!cat .production-grade.yamlare executed automatically without user intervention upon loading the skill. - [REMOTE_CODE_EXECUTION]:
- The skill implements an automated update mechanism that fetches versioning data and downloads code from
github.com/buiphucminhtam/forgewrightviagit clone. - It silently executes
npx --yes forgenexus analyzeduring the auto-initialization of project intelligence. - The skill provides a 'Power Level' setup that installs external software packages like
notebooklm-mcp,crawl4ai, and@anthropic-ai/midscenevia pip and npm. - [EXTERNAL_DOWNLOADS]: Fetches update data and fetches code from external GitHub repositories.
- [PROMPT_INJECTION]: The orchestrator includes a middleware layer (
DryRunContext) designed for 'system prompt injection,' which, while intended as a functional feature for dry-run modes, represents a mechanism for dynamic modification of the agent's core instructions. - [DATA_EXFILTRATION]: High attack surface for indirect prompt injection due to the extensive ingestion of untrusted external content and a wide range of powerful capabilities.
- Ingestion points: Processes external data from web scraping (via crawl4ai), NotebookLM research, and various codebase files (SKILL.md, Phase 4).
- Boundary markers: Utilizes structured prompt templates (CO-STAR, RISEN) and XML tags to delimit ingested content (SKILL.md).
- Capability inventory: Has the ability to execute terminal commands, modify the filesystem, and perform network operations.
- Sanitization: Implements a 'Sensitive File Protection' protocol to prevent reading .env files without approval and uses a 'tool output sandbox' to redact secrets (SKILL.md).
Audit Metadata