adopt

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell scripts within the project repository, such as .claude/scripts/gdd-structure-check.sh and .claude/scripts/migrate-v1-config.sh. These are used to deterministically verify the internal structure of documents and automate configuration migration between template versions.
  • [DYNAMIC_CONTEXT_INJECTION]: A dynamic context injection pattern is used at the start of the skill (!bash ...) to resolve configuration keys like automation and workflow. This script execution happens at skill load time to set the operational environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from the project's documentation files.
  • Ingestion points: Reads and audits user-provided Markdown files located at design/gdd/*.md, docs/architecture/adr-*.md, and production/epics/**/*.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands were found in the skill's instructions.
  • Capability inventory: The skill has access to Bash (script execution), Write (file creation), and AskUserQuestion tools.
  • Sanitization: The skill mitigates risks by relying on external script output and specific grep patterns for auditing rather than directly processing raw content as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — adopt