architecture-decision
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses a shell command execution (
!bash) at the top of its SKILL.md file to resolve project-specific configuration keys likereview_modeandworkflowvia a local script,yaml-helper.sh, located in the project's hooks directory. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the local file system, creating a potential attack surface for indirect prompt injection.
- Ingestion points: The skill reads data from existing ADRs (
docs/architecture/*.md), Design Documents (design/gdd/*.md), and Engine Reference files (docs/engine-reference/**). - Boundary markers: The instructions do not specify the use of clear delimiters or instructions to ignore embedded commands within the files being read.
- Capability inventory: The skill has access to sensitive tools including file writing (
Write,Edit), shell command execution (Bash), and subagent delegation (Agent). - Sanitization: There is no explicit mechanism described for sanitizing or validating the content read from files before it is processed by the model.
Audit Metadata