squads-team
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository files, project instructions, and issue trackers, which creates a potential surface for indirect prompt injection. 1. Ingestion points: Repository state, project instructions, and external web content as described in SKILL.md. 2. Boundary markers: The skill contains explicit instructions to ignore any instructions embedded in untrusted external repository or web content. 3. Capability inventory: The agent can delegate work to subagents and perform file modifications across the repository. 4. Sanitization: The delivery pipeline requires mandatory independent QA and Code Review gates to verify all implementation artifacts before they are integrated.
- [COMMAND_EXECUTION]: The skill involves managing lifecycle tasks for engineering workflows. Evidence: The coordination-contract.md reference describes the management of background processes, ports, and worktrees, including instructions for safe resource cleanup.
Audit Metadata