ccdawn-brt
Warn
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The instructions permit the agent to bypass safety and verification steps if it determines that intent and safety are met by other evidence ("能以同等或更强证据满足意图、安全和验证时,允许合并或跳过过程步骤"). This grants the model discretion to override hard-coded safety constraints in favor of perceived reasoning efficiency.
- [PROMPT_INJECTION]: The skill serves as a primary adaptation layer for all user input, creating a surface for indirect prompt injection. Ingestion occurs at the BRT layer where user messages are translated into intent. While boundary markers such as "Alignment Handshakes" and "Collaborative Calibration" are defined to mirror intent, the skill lacks rigorous technical sanitization before passing instructions to high-capability downstream owners (e.g., implementation and planning skills). The capability inventory includes file writes and command execution through these delegated owners, creating a risk that malicious data could influence system-level actions.
- [EXTERNAL_DOWNLOADS]: The skill maintains a list of external GitHub repositories and community skills in
references/github-skill-candidates.md. While many sources are well-known organizations, several candidates originate from individual, unverified developer accounts (e.g.,shepsci,wenmin-wu,bladnman). The skill encourages installing these tools when fallback mechanisms are insufficient, which introduces potential security risks from third-party code.
Audit Metadata