bug-triage

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted bug report data which could contain malicious instructions.
  • Ingestion points: Reads bug reports from production/qa/bugs/*.md and production/qa/bugs.md (Step 2a), and sprint plans from production/sprints/ (Step 2b).
  • Boundary markers: Absent; instructions do not specify using delimiters when reading bug report contents in SKILL.md.
  • Capability inventory: The skill uses Write and Edit tools to generate reports and modify sprint data in SKILL.md.
  • Sanitization: Absent; the skill does not mention sanitizing or escaping the content of bug reports before re-evaluating priority and severity.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill performs shell command execution at load time using platform-specific syntax.
  • Evidence: The !bash command at the top of SKILL.md executes ${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh.
  • Function: It resolves project configuration keys via a local helper script.
  • [COMMAND_EXECUTION]: The skill is configured to use a local shell script for project configuration.
  • Evidence: The Bash tool is restricted in the frontmatter to a specific local path: bash "*/.claude/skills/bug-triage/../../hooks/yaml-helper.sh" resolve_config *.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — bug-triage