create-control-manifest

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests Architecture Decision Records (ADRs) and project configuration files to extract actionable rules. Maliciously crafted content in these external files could potentially influence the agent's behavior during the extraction process or affect downstream tasks that consume the generated manifest.
  • Ingestion points: The skill reads from docs/architecture/adr-*.md, project.yaml, and .claude/docs/technical-preferences.md (Step 1 and Step 2).
  • Boundary markers: Absent. The skill extracts content based on section headers but lacks explicit instructions to ignore embedded prompts within the extracted text.
  • Capability inventory: The skill has permissions to write files (docs/architecture/control-manifest.md), execute specific local Bash commands, and spawn a technical review agent.
  • Sanitization: Content is filtered by specific section headers (e.g., ## Decision) using Grep, but the raw text within these sections is not sanitized before being used in the manifest generation.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill executes a project-local script during the load process to resolve environment configuration.
  • Evidence: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation``
  • Context: This is a benign use of project-specific tooling to synchronize the skill's automation settings with the local project configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — create-control-manifest