architecture-review
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill employs the
!commandsyntax to execute a bash script (yaml-helper.sh) at skill load time. This mechanism is used to resolve configuration keys for automation and workflow modes. Execution of shell commands during the initial loading phase is a security concern as it occurs before AI safety review.\n- [COMMAND_EXECUTION]: The skill uses theBashtool to run local scripts such asreview-receipts.shandadr-dep-graph.sh. These scripts are responsible for checking file hashes and calculating dependency orders for architectural decisions. These operations involve executing code within the project environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external design data, creating a surface for indirect instructions. 1. Ingestion points: The skill reads content from all Game Design Documents (design/gdd/*.md) and Architectural Decision Records (docs/architecture/adr-*.md). 2. Boundary markers: No explicit boundary markers or 'ignore' instructions are present for the ingested content. 3. Capability inventory: The skill has the capability to write files (Write), execute local bash scripts (Bash), and spawn further sub-agents (Agent). 4. Sanitization: The skill uses targetedGrepextraction to focus on technical sections, which reduces the data volume but does not perform sanitization of the extracted content.
Audit Metadata