brainstorm
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is authorized to run a local bash script
yaml-helper.shlocated in the project hooks directory. The script is used for resolving configuration parameters and its execution is restricted to specific commands. - [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the
!bashsyntax to execute a configuration resolution script at load time. This allows the skill to dynamically adjust parameters likereview_modeandworkflowbased on the project environment. - [INDIRECT_PROMPT_INJECTION]: The skill reads existing design documents and project metadata to maintain continuity between brainstorming sessions.
- Ingestion points:
Readoperations ondesign/gdd/game-concept.md,design/gdd/game-pillars.md, andproject.yamlin SKILL.md. - Boundary markers: The skill employs interactive
AskUserQuestioncalls and manual confirmation steps to validate generated content, acting as a control against accidental instruction following. - Capability inventory: Authorized to execute a specific local bash script, write design documents to the filesystem, and spawn sub-agents.
- Sanitization: External content from project files is not explicitly sanitized for prompt injection patterns before being used in the brainstorming workflow.
Audit Metadata