bug-report
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill executes a project-specific script during the initial load phase to resolve configuration values.
- Evidence:
!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automationinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill processes external, potentially untrusted data from user descriptions and source files to generate reports and verify bug fixes.
- Ingestion points: User-supplied bug descriptions and source code files accessed via
ReadandGlobtools. - Boundary markers: The skill does not implement specific delimiters or instructions to ignore embedded commands within the processed data.
- Capability inventory: The skill has access to
Read,Glob,Grep,Bash,Write, andEdittools. - Sanitization: No explicit logic is defined to sanitize or validate the content of ingested files before processing.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to run project tests as part of the bug verification cycle. - Evidence: Phase 2C in
SKILL.mdinstructs the agent to run related tests via Bash and report the results.
Audit Metadata