create-epics

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from various external files (GDDs, ADRs, and registries) which could contain malicious instructions designed to influence the agent's behavior during the epic creation process.
  • Ingestion points: The skill reads data from files matching design/gdd/*.md, docs/architecture/architecture.md, docs/architecture/adr-*.md, docs/architecture/tr-registry.yaml, and docs/engine-reference/*/VERSION.md.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when interpolating content from these external documents into the agent's context.
  • Capability inventory: The skill has access to tools including Read, Glob, Grep, Write, Agent (for spawning sub-agents), AskUserQuestion, and Bash (restricted to configuration resolution).
  • Sanitization: The skill does not describe any sanitization or validation steps for the content ingested from the external markdown and YAML files.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic context injection syntax (!) to execute a shell command when the skill is first loaded into the agent's environment.
  • Evidence: Verbatim string: ! bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,workflow,docs.density,story_granularity,system_overrides``
  • Context: This is used for project-specific configuration resolution, allowing the skill to adapt to local environment settings (like review_mode and workflow tiers) before processing starts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — create-epics