help

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the exclamation-backtick syntax in its body to execute shell commands when the skill is loaded by the agent platform.
  • Evidence: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys project.stage,workflow in SKILL.md.
  • Evidence: !echo "Latest sprint: $(ls -t production/sprints/*.md 2>/dev/null | head -1 || echo 'none')"; echo "Session state: $(head -5 production/session-state/active.md 2>/dev/null || echo 'none')" in SKILL.md.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute local shell scripts found within the project's directory structure to perform artifact analysis.
  • Evidence: Bash: bash .claude/scripts/artifact-check.sh --phase [current-phase] in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources, including session logs, YAML catalogs, and frontmatter from other skills, to determine its recommendations.
  • Ingestion points: .claude/docs/workflow-catalog.yaml, production/session-state/active.md, production/sprint-status.yaml, and .claude/skills/*/SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters or "ignore instructions" warnings when processing the contents of these files.
  • Capability inventory: The skill has access to Bash, Read, Glob, and Grep tools.
  • Sanitization: No sanitization or validation of the ingested content is specified before it is used to influence the agent's logic.
  • [PROMPT_INJECTION]: The markdown body contains a pre-defined verdict string which may be intended to influence automated safety scanners or agent self-reporting behavior.
  • Evidence: Verdict: **COMPLETE** — next steps identified.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — help