launch-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the platform-specific syntax to execute a local configuration script immediately upon loading. This output is used to resolve project configuration and tailor the checklist logic.
- [COMMAND_EXECUTION]: The skill uses the Bash tool to run a configuration resolver script. Access to this tool is limited to the relative path provided in the skill frontmatter.
- [INDIRECT_PROMPT_INJECTION]: The skill reads and scans the entire codebase and project documentation, creating a surface for instructions embedded in data to influence agent behavior.
- Ingestion points:
CLAUDE.md,production/milestones/,production/releases/,design/live-ops/content-calendar.md, and all source and asset files scanned for markers. - Boundary markers: The instructions do not include specific delimiters or explicit warnings to ignore commands within the scanned files.
- Capability inventory: The skill uses Read, Glob, Grep, Write, and Bash tools to perform its tasks.
- Sanitization: There is no evidence of sanitization or filtering for the content read from external project files before it is processed and reported.
Audit Metadata