brainstorm

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is authorized to run a local bash script yaml-helper.sh located in the project hooks directory. The script is used for resolving configuration parameters and its execution is restricted to specific commands.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !bash syntax to execute a configuration resolution script at load time. This allows the skill to dynamically adjust parameters like review_mode and workflow based on the project environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads existing design documents and project metadata to maintain continuity between brainstorming sessions.
  • Ingestion points: Read operations on design/gdd/game-concept.md, design/gdd/game-pillars.md, and project.yaml in SKILL.md.
  • Boundary markers: The skill employs interactive AskUserQuestion calls and manual confirmation steps to validate generated content, acting as a control against accidental instruction following.
  • Capability inventory: Authorized to execute a specific local bash script, write design documents to the filesystem, and spawn sub-agents.
  • Sanitization: External content from project files is not explicitly sanitized for prompt injection patterns before being used in the brainstorming workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:22 PM
Security Audit — agent-trust-hub — brainstorm