asset-spec
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from various project documents which could serve as a vector for indirect prompt injection.
- Ingestion points: The skill reads from
design/gdd/*.md,design/narrative/,design/levels/*.md, anddesign/art/art-bible.md(SKILL.md, Phase 1). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat this external content as untrusted data or to ignore embedded commands.
- Capability inventory: The skill has the ability to write files (
Write,Edit) and spawn sub-agents (Agent) which execute complex instructions based on the ingested data. - Sanitization: No sanitization or validation of the text content extracted from design documents is performed before it is used to generate prompts or specifications.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes dynamic context injection to execute a local shell command when the skill is loaded.
- Evidence: The line
!`bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation`triggers a shell command execution to resolve configuration settings. - Context: This execution occurs silently at load time, although in this instance, it targets a local project script for configuration purposes rather than external or sensitive resources.
Audit Metadata