architecture-review

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill employs the !command syntax to execute a bash script (yaml-helper.sh) at skill load time. This mechanism is used to resolve configuration keys for automation and workflow modes. Execution of shell commands during the initial loading phase is a security concern as it occurs before AI safety review.\n- [COMMAND_EXECUTION]: The skill uses the Bash tool to run local scripts such as review-receipts.sh and adr-dep-graph.sh. These scripts are responsible for checking file hashes and calculating dependency orders for architectural decisions. These operations involve executing code within the project environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external design data, creating a surface for indirect instructions. 1. Ingestion points: The skill reads content from all Game Design Documents (design/gdd/*.md) and Architectural Decision Records (docs/architecture/adr-*.md). 2. Boundary markers: No explicit boundary markers or 'ignore' instructions are present for the ingested content. 3. Capability inventory: The skill has the capability to write files (Write), execute local bash scripts (Bash), and spawn further sub-agents (Agent). 4. Sanitization: The skill uses targeted Grep extraction to focus on technical sections, which reduces the data volume but does not perform sanitization of the extracted content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — architecture-review