gate-check
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple project-specific files to determine phase advancement.\n
- Ingestion points: The skill reads user-created files including Game Design Documents (
design/gdd/*.md), Architecture Decision Records (docs/architecture/*.md), playtest reports (production/qa/playtests/), and build smoke reports (production/qa/smoke-*.md).\n - Boundary markers: External content is interpolated directly into the context for assessment without the use of explicit delimiters or instructions to ignore embedded directives.\n
- Capability inventory: The skill has significant permissions, including spawning parallel sub-agents via the Agent tool, writing to core configuration files (
project.yaml), and executing shell scripts.\n - Sanitization: No escaping or validation is performed on the content of the read files before they are processed by the agent.\n- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic context injection pattern (
!command) to execute a local configuration helper script (yaml-helper.sh) during initialization. This call resolves configuration keys used to control the skill's behavior.\n- [COMMAND_EXECUTION]: The skill relies on several local bash scripts (artifact-check.sh,gdd-structure-check.sh,adr-dep-graph.sh) to gather repository data. These commands incorporate parameters such as the target phase name derived from user arguments.
Audit Metadata