bug-triage
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted bug report data which could contain malicious instructions.
- Ingestion points: Reads bug reports from
production/qa/bugs/*.mdandproduction/qa/bugs.md(Step 2a), and sprint plans fromproduction/sprints/(Step 2b). - Boundary markers: Absent; instructions do not specify using delimiters when reading bug report contents in
SKILL.md. - Capability inventory: The skill uses
WriteandEdittools to generate reports and modify sprint data inSKILL.md. - Sanitization: Absent; the skill does not mention sanitizing or escaping the content of bug reports before re-evaluating priority and severity.
- [DYNAMIC_CONTEXT_INJECTION]: The skill performs shell command execution at load time using platform-specific syntax.
- Evidence: The
!bashcommand at the top ofSKILL.mdexecutes${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh. - Function: It resolves project configuration keys via a local helper script.
- [COMMAND_EXECUTION]: The skill is configured to use a local shell script for project configuration.
- Evidence: The
Bashtool is restricted in the frontmatter to a specific local path:bash "*/.claude/skills/bug-triage/../../hooks/yaml-helper.sh" resolve_config *.
Audit Metadata