design-review
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from user-provided design documents and passes it to specialist agents (such as game-designer, systems-designer, and ai-programmer) without boundary markers or instructions to ignore embedded commands. This creates a surface for indirect prompt injection where a malicious document could influence the specialist agents' findings or behavior.
- Ingestion points: The skill reads the full content of the target design document in Phase 1 and passes it to specialists in Phase 3b.
- Boundary markers: Absent. The GDD content is interpolated directly into the specialist agent prompts.
- Capability inventory: The skill uses the Agent tool to spawn sub-sessions, Bash to execute local scripts, and Write/Edit to modify project tracking files.
- Sanitization: Absent.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !command syntax to execute a shell script at load time to resolve configuration variables like review_mode and workflow. While the specific command (yaml-helper.sh resolve_config) appears intended for configuration, this mechanism executes shell commands automatically when the skill is loaded.
- Evidence: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,workflow,system_overrides in SKILL.md.
- [COMMAND_EXECUTION]: The skill executes multiple local shell scripts to perform freshness checks and structure validation. It employs parent directory traversal (../../) to access scripts outside the skill's specific directory.
- Evidence: bash .claude/scripts/review-receipts.sh and bash .claude/scripts/gdd-structure-check.sh in SKILL.md.
Audit Metadata