stream
Warn
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes several shell commands for project management and verification, including 'git log', 'git diff', 'git commit', 'git push', 'pnpm exec vitest', and 'npx tsc'. It also performs file system operations such as deleting plan files and status files upon completion of the 'final' stream.
- [REMOTE_CODE_EXECUTION]: The skill dynamically executes a local Python script ('skills/ui-ux-pro-max/scripts/search.py') using arguments such as 'keywords', 'domain', and 'stack' that are parsed directly from the markdown plan files. This represents a potential command injection surface if the plan files contain malicious shell characters or commands.
- [PROMPT_INJECTION]:
- Ingestion points: The skill ingests and parses untrusted data from markdown plan files ('docs/plans/*.md') to determine stream dependencies, file ownership, and required skill sets.
- Boundary markers: No explicit delimiters or boundary markers are established to separate the plan's data from the agent's instructions, increasing the risk of the agent obeying instructions embedded within the plan file.
- Capability inventory: The skill has access to high-privilege tools, including arbitrary shell execution, file deletion, git repository modification, and background agent orchestration.
- Sanitization: The instructions do not specify any validation or sanitization for the keywords, file paths, or skill names extracted from the plan files before they are used in shell commands or logic branching.
Audit Metadata