map-systems

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill employs the !commandsyntax at the top of `SKILL.md` to execute a shell command:!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys ... ``. This command runs automatically when the skill is accessed, replacing the placeholder with the script output.
  • [COMMAND_EXECUTION]: The skill frontmatter and body reference an external script yaml-helper.sh via a path traversal sequence (../../hooks/). This script resides outside the skill's own directory. The allowed-tools section explicitly permits the execution of this specific script with arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from project files to drive its design decomposition workflow.
  • Ingestion points: Reads design/gdd/game-concept.md, design/game-brief.md, and other project documents in Phase 1.
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions within the read files.
  • Capability inventory: The skill uses Write and Edit for file modification, Agent for spawning new sessions, and a scoped Bash tool.
  • Sanitization: No content sanitization or validation of the ingested markdown data is performed before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — map-systems