design-review

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from user-provided design documents and passes it to specialist agents (such as game-designer, systems-designer, and ai-programmer) without boundary markers or instructions to ignore embedded commands. This creates a surface for indirect prompt injection where a malicious document could influence the specialist agents' findings or behavior.
  • Ingestion points: The skill reads the full content of the target design document in Phase 1 and passes it to specialists in Phase 3b.
  • Boundary markers: Absent. The GDD content is interpolated directly into the specialist agent prompts.
  • Capability inventory: The skill uses the Agent tool to spawn sub-sessions, Bash to execute local scripts, and Write/Edit to modify project tracking files.
  • Sanitization: Absent.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !command syntax to execute a shell script at load time to resolve configuration variables like review_mode and workflow. While the specific command (yaml-helper.sh resolve_config) appears intended for configuration, this mechanism executes shell commands automatically when the skill is loaded.
  • Evidence: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,workflow,system_overrides in SKILL.md.
  • [COMMAND_EXECUTION]: The skill executes multiple local shell scripts to perform freshness checks and structure validation. It employs parent directory traversal (../../) to access scripts outside the skill's specific directory.
  • Evidence: bash .claude/scripts/review-receipts.sh and bash .claude/scripts/gdd-structure-check.sh in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — design-review