adopt
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell scripts within the project repository, such as
.claude/scripts/gdd-structure-check.shand.claude/scripts/migrate-v1-config.sh. These are used to deterministically verify the internal structure of documents and automate configuration migration between template versions. - [DYNAMIC_CONTEXT_INJECTION]: A dynamic context injection pattern is used at the start of the skill (
!bash ...) to resolve configuration keys likeautomationandworkflow. This script execution happens at skill load time to set the operational environment. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from the project's documentation files.
- Ingestion points: Reads and audits user-provided Markdown files located at
design/gdd/*.md,docs/architecture/adr-*.md, andproduction/epics/**/*.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands were found in the skill's instructions.
- Capability inventory: The skill has access to
Bash(script execution),Write(file creation), andAskUserQuestiontools. - Sanitization: The skill mitigates risks by relying on external script output and specific
greppatterns for auditing rather than directly processing raw content as instructions.
Audit Metadata