prompt-engineer

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the !command syntax to execute shell commands at load time for context gathering. It runs cat on several local files including .production-grade.yaml, .forgewright/codebase-context.md, and .forgewright/settings.md. While the commands themselves are benign and restricted to reading project files, this mechanism automatically incorporates external file content into the agent's core instruction set.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files and interpolates it directly into the prompt stream, creating an attack surface for indirect instructions.\n
  • Ingestion points: SKILL.md (lines 12-17, 26) uses dynamic context injection to load file contents.\n
  • Boundary markers: Absent. The content of the files is injected directly into the skill's instruction block without delimiters or instructions to ignore embedded commands.\n
  • Capability inventory: The skill is designed to perform file system operations, specifically creating prompt templates, evaluation datasets, and Python evaluation scripts (evaluation/scripts/eval_<feature>.py).\n
  • Sanitization: No validation or sanitization of the injected file content is performed before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 07:28 PM
Security Audit — agent-trust-hub — prompt-engineer