launch-checklist

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the platform-specific syntax to execute a local configuration script immediately upon loading. This output is used to resolve project configuration and tailor the checklist logic.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run a configuration resolver script. Access to this tool is limited to the relative path provided in the skill frontmatter.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and scans the entire codebase and project documentation, creating a surface for instructions embedded in data to influence agent behavior.
  • Ingestion points: CLAUDE.md, production/milestones/, production/releases/, design/live-ops/content-calendar.md, and all source and asset files scanned for markers.
  • Boundary markers: The instructions do not include specific delimiters or explicit warnings to ignore commands within the scanned files.
  • Capability inventory: The skill uses Read, Glob, Grep, Write, and Bash tools to perform its tasks.
  • Sanitization: There is no evidence of sanitization or filtering for the content read from external project files before it is processed and reported.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — launch-checklist