prompt-engineer
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!commandsyntax to execute shell commands at load time for context gathering. It runscaton several local files including.production-grade.yaml,.forgewright/codebase-context.md, and.forgewright/settings.md. While the commands themselves are benign and restricted to reading project files, this mechanism automatically incorporates external file content into the agent's core instruction set.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files and interpolates it directly into the prompt stream, creating an attack surface for indirect instructions.\n - Ingestion points:
SKILL.md(lines 12-17, 26) uses dynamic context injection to load file contents.\n - Boundary markers: Absent. The content of the files is injected directly into the skill's instruction block without delimiters or instructions to ignore embedded commands.\n
- Capability inventory: The skill is designed to perform file system operations, specifically creating prompt templates, evaluation datasets, and Python evaluation scripts (
evaluation/scripts/eval_<feature>.py).\n - Sanitization: No validation or sanitization of the injected file content is performed before it is processed by the agent.
Audit Metadata