content-audit
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the
!commandsyntax at the start of the file to executebash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys workflow,automation. This command runs automatically when the skill is loaded or opened by the agent, before any user interaction, using a path traversal sequence to reach a script outside the skill's own directory. - [COMMAND_EXECUTION]: The skill is specifically configured in its frontmatter to allow the
Bashtool to execute ayaml-helper.shscript. This script is intended to resolve configuration parameters (workflow,automation) but involves executing local shell scripts at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources within the project environment.
- Ingestion points: The skill reads all markdown files in
design/gdd/, registry entries indesign/registry/entities.yaml, and various asset data files (including.json,.yaml,.csv, and.ink) across the project directories. - Boundary markers: The instructions do not include specific delimiters or "ignore embedded instructions" warnings to isolate the content parsed from these external files during the count extraction phase.
- Capability inventory: The agent has access to
Bash,Write,Read,Glob, andGrepwhile processing and acting upon this ingested data. - Sanitization: There are no sanitization or validation steps described for the data extracted from design documents before it is interpolated into the final audit reports or used to drive subsequent agent actions like creating backlog stories.
Audit Metadata