help
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the exclamation-backtick syntax in its body to execute shell commands when the skill is loaded by the agent platform.
- Evidence:
!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys project.stage,workflowinSKILL.md. - Evidence:
!echo "Latest sprint: $(ls -t production/sprints/*.md 2>/dev/null | head -1 || echo 'none')"; echo "Session state: $(head -5 production/session-state/active.md 2>/dev/null || echo 'none')"inSKILL.md. - [COMMAND_EXECUTION]: The skill instructions direct the agent to execute local shell scripts found within the project's directory structure to perform artifact analysis.
- Evidence:
Bash: bash .claude/scripts/artifact-check.sh --phase [current-phase]inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources, including session logs, YAML catalogs, and frontmatter from other skills, to determine its recommendations.
- Ingestion points:
.claude/docs/workflow-catalog.yaml,production/session-state/active.md,production/sprint-status.yaml, and.claude/skills/*/SKILL.md. - Boundary markers: The instructions lack explicit delimiters or "ignore instructions" warnings when processing the contents of these files.
- Capability inventory: The skill has access to
Bash,Read,Glob, andGreptools. - Sanitization: No sanitization or validation of the ingested content is specified before it is used to influence the agent's logic.
- [PROMPT_INJECTION]: The markdown body contains a pre-defined verdict string which may be intended to influence automated safety scanners or agent self-reporting behavior.
- Evidence:
Verdict: **COMPLETE** — next steps identified.
Audit Metadata