create-epics
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from various external files (GDDs, ADRs, and registries) which could contain malicious instructions designed to influence the agent's behavior during the epic creation process.
- Ingestion points: The skill reads data from files matching
design/gdd/*.md,docs/architecture/architecture.md,docs/architecture/adr-*.md,docs/architecture/tr-registry.yaml, anddocs/engine-reference/*/VERSION.md. - Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when interpolating content from these external documents into the agent's context.
- Capability inventory: The skill has access to tools including
Read,Glob,Grep,Write,Agent(for spawning sub-agents),AskUserQuestion, andBash(restricted to configuration resolution). - Sanitization: The skill does not describe any sanitization or validation steps for the content ingested from the external markdown and YAML files.
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic context injection syntax (
!) to execute a shell command when the skill is first loaded into the agent's environment. - Evidence: Verbatim string:
!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,workflow,docs.density,story_granularity,system_overrides`` - Context: This is used for project-specific configuration resolution, allowing the skill to adapt to local environment settings (like
review_modeandworkflowtiers) before processing starts.
Audit Metadata