qa-plan

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !bash syntax in the markdown body to execute a shell script (yaml-helper.sh) at the time the skill is loaded. This execution is used to resolve configuration keys related to automation and workflow tiers.
  • [COMMAND_EXECUTION]: The skill executes a local script located at ${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh. This script is used both for pre-load configuration resolution and within the allowed-tools scoping to manage YAML-based settings.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests data from external files, including story files (production/epics/**/story-*.md) and Game Design Documents (GDDs). Malicious instructions embedded in these files could theoretically influence the agent's output during the plan generation phase.
  • Ingestion points: Story files (production/epics/), GDD files (design/gdd/), and sprint plans (production/sprints/).
  • Boundary markers: None explicitly defined for isolating the content of the Acceptance Criteria or Engine notes sections during processing.
  • Capability inventory: The skill has access to Write, Edit, and limited Bash capabilities, which are used to generate the final QA plan and back-fill test cases into story files.
  • Sanitization: No specific sanitization or escaping of external content is mentioned before it is interpolated into the test plan templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — qa-plan