project-stage-detect

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax to execute a shell command (yaml-helper.sh) at load time to resolve project configuration keys for workflow and automation tiers. This command is scoped to a local script provided within the project environment.
  • [COMMAND_EXECUTION]: The skill executes a local script .claude/scripts/artifact-check.sh via the Bash tool to perform a deterministic scan of project artifacts. The output is used for objective project state analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it ingests data from local project files that could contain malicious instructions.
  • Ingestion points: Reads content from design/, src/, production/, and other project directories (SKILL.md).
  • Boundary markers: None explicitly defined to distinguish between processed project data and skill logic.
  • Capability inventory: The skill has access to Bash, Write, Read, Glob, and Grep tools.
  • Sanitization: No specific sanitization is mentioned for external content; however, the skill implements a mandatory human-in-the-loop checkpoint in Step 6 before writing the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — project-stage-detect