dominion

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection through its 'briefing packet' model.
  • Ingestion points: The orchestrator reads plan files (docs/plans/*.md), CLAUDE.md, and project source files to create briefing packets.
  • Boundary markers: The instructions for sub-agents interpolate untrusted data (e.g., {stream_section_verbatim}, {per_skill_rule_excerpts}) without explicit delimiters or warnings to ignore embedded instructions.
  • Capability inventory: Dispatched sub-agents have access to powerful tools including Bash, Write, Edit, and Agent, allowing for significant system impact if manipulated.
  • Sanitization: The skill explicitly uses 'verbatim' extraction for content, providing no validation or filtering of the processed text. An attacker who can modify a plan file or a project file could inject instructions that the sub-agents would treat as the 'authoritative contract'.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:36 AM
Security Audit — agent-trust-hub — dominion