workflow-tdd-plan
Warn
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to execute shell commands. In the 'Phase 4: Conflict Resolution' section, the user-providedtaskDescriptionis interpolated directly into a command string for theccw clitool without escaping or sanitization. This exposes the environment to command injection if the input contains shell metacharacters like semicolons or quotes.\n - Evidence: The code snippet in Phase 4 uses
Bash({ command:ccw cli -p "... TASK DESCRIPTION: ${taskDescription}" ..., run_in_background: true }).\n- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting external user data and propagating it to several sub-agents.\n - Ingestion points: The
taskDescriptionderived from$ARGUMENTSinSKILL.mdis passed to thecontext-search-agent,action-planning-agent, and theccw clianalysis tool.\n - Boundary markers: The input is labeled but not encapsulated within secure delimiters that would prevent sub-agents from following instructions embedded within the user's task description.\n
- Capability inventory: The skill has access to sensitive tools such as
Bash,Write,Edit, andspawn_agentacross its seven-phase pipeline.\n - Sanitization: No sanitization or validation is performed on the user's input before it is used to construct prompts for the sub-agents.
Audit Metadata