dev-story
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill's YAML frontmatter contains a dynamic context injection pattern that executes a local script (
yaml-helper.sh) viabashto resolve project-specific configuration keys at load time. This is used for benign environment setup. - [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform routine development operations, such as calculating file sizes, running headless engine imports for syntax validation, and launching project builds to capture screenshots for visual verification. These commands are scoped to the project's development workflow. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external project documentation, including story files, architecture records (ADRs), and requirement registries. This information is processed and used to brief sub-agents, creating a surface for indirect prompt injection. The skill implements mitigation strategies by using targeted extraction (distilling summaries), enforcing freshness gates via version-date matching, and providing explicit instructions to agents regarding which files are authoritative for their specific task.
Audit Metadata