playtest-report
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!syntax to execute a shell command during the skill loading phase:!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation. While the command is used for configuration resolution and targets a local script, this mechanism allows code execution outside of the standard interactive prompt cycle. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in Phase 2B, where it reads raw playtest notes from a user-provided path.
- Ingestion points: Reads raw notes from a path specified in the
analyzeargument during Phase 2B. - Boundary markers: None identified; the skill instructions do not specify delimiters or instructions to ignore embedded commands within the notes.
- Capability inventory: The skill has the ability to write files (Phase 4), spawn sub-agents using the
Agenttool (Phase 3b), and execute specific local shell scripts via the restrictedBashtool. - Sanitization: No explicit sanitization or validation of the content of the playtest notes is described before it is used to populate templates or inform the Creative Director agent.
- [COMMAND_EXECUTION]: The skill's configuration limits the
Bashtool to a specific local script:bash "*/.claude/skills/playtest-report/../../hooks/yaml-helper.sh" resolve_config *. This is used to resolve project-specific configuration for review modes and automation levels.
Audit Metadata