production-grade

Warn

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: Extensive use of dynamic context injection (the !command syntax) in SKILL.md to silently execute shell commands and read project-specific files at skill load time.
  • Evidence: !git status, !cat CLAUDE.md, and !cat .production-grade.yaml are executed automatically without user intervention upon loading the skill.
  • [REMOTE_CODE_EXECUTION]:
  • The skill implements an automated update mechanism that fetches versioning data and downloads code from github.com/buiphucminhtam/forgewright via git clone.
  • It silently executes npx --yes forgenexus analyze during the auto-initialization of project intelligence.
  • The skill provides a 'Power Level' setup that installs external software packages like notebooklm-mcp, crawl4ai, and @anthropic-ai/midscene via pip and npm.
  • [EXTERNAL_DOWNLOADS]: Fetches update data and fetches code from external GitHub repositories.
  • [PROMPT_INJECTION]: The orchestrator includes a middleware layer (DryRunContext) designed for 'system prompt injection,' which, while intended as a functional feature for dry-run modes, represents a mechanism for dynamic modification of the agent's core instructions.
  • [DATA_EXFILTRATION]: High attack surface for indirect prompt injection due to the extensive ingestion of untrusted external content and a wide range of powerful capabilities.
  • Ingestion points: Processes external data from web scraping (via crawl4ai), NotebookLM research, and various codebase files (SKILL.md, Phase 4).
  • Boundary markers: Utilizes structured prompt templates (CO-STAR, RISEN) and XML tags to delimit ingested content (SKILL.md).
  • Capability inventory: Has the ability to execute terminal commands, modify the filesystem, and perform network operations.
  • Sanitization: Implements a 'Sensitive File Protection' protocol to prevent reading .env files without approval and uses a 'tool output sandbox' to redact secrets (SKILL.md).
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — production-grade