consistency-check
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to run local scripts (yaml-helper.sh) and system commands likegit log. Theallowed-toolsconfiguration specifically restrictsBashusage to a pre-defined script path, following the principle of least privilege. - [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the load-time execution syntax
!to run a shell command:!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config. This is used to resolve skill settings from the project environment. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external markdown files and a YAML registry to drive automated updates and failure logging.
- Ingestion points:
design/registry/entities.yamlanddesign/gdd/*.md. - Boundary markers: Absent; the skill does not use specific delimiters to isolate potentially malicious instructions within GDD content.
- Capability inventory:
Read,Glob,Grep,Write,Edit,Bash,AskUserQuestion. - Sanitization: Absent; content from GDD files is directly compared and potentially logged or written back to the registry without explicit filtering or escaping.
Audit Metadata