workflow-tdd-plan

Warn

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute shell commands. In the 'Phase 4: Conflict Resolution' section, the user-provided taskDescription is interpolated directly into a command string for the ccw cli tool without escaping or sanitization. This exposes the environment to command injection if the input contains shell metacharacters like semicolons or quotes.\n
  • Evidence: The code snippet in Phase 4 uses Bash({ command: ccw cli -p "... TASK DESCRIPTION: ${taskDescription}" ..., run_in_background: true }).\n- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting external user data and propagating it to several sub-agents.\n
  • Ingestion points: The taskDescription derived from $ARGUMENTS in SKILL.md is passed to the context-search-agent, action-planning-agent, and the ccw cli analysis tool.\n
  • Boundary markers: The input is labeled but not encapsulated within secure delimiters that would prevent sub-agents from following instructions embedded within the user's task description.\n
  • Capability inventory: The skill has access to sensitive tools such as Bash, Write, Edit, and spawn_agent across its seven-phase pipeline.\n
  • Sanitization: No sanitization or validation is performed on the user's input before it is used to construct prompts for the sub-agents.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 22, 2026, 05:45 AM