project-stage-detect
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!syntax to execute a shell command (yaml-helper.sh) at load time to resolve project configuration keys for workflow and automation tiers. This command is scoped to a local script provided within the project environment. - [COMMAND_EXECUTION]: The skill executes a local script
.claude/scripts/artifact-check.shvia theBashtool to perform a deterministic scan of project artifacts. The output is used for objective project state analysis. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it ingests data from local project files that could contain malicious instructions.
- Ingestion points: Reads content from
design/,src/,production/, and other project directories (SKILL.md). - Boundary markers: None explicitly defined to distinguish between processed project data and skill logic.
- Capability inventory: The skill has access to
Bash,Write,Read,Glob, andGreptools. - Sanitization: No specific sanitization is mentioned for external content; however, the skill implements a mandatory human-in-the-loop checkpoint in Step 6 before writing the final report.
Audit Metadata