qa-plan
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the
!bashsyntax in the markdown body to execute a shell script (yaml-helper.sh) at the time the skill is loaded. This execution is used to resolve configuration keys related to automation and workflow tiers. - [COMMAND_EXECUTION]: The skill executes a local script located at
${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh. This script is used both for pre-load configuration resolution and within theallowed-toolsscoping to manage YAML-based settings. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests data from external files, including story files (
production/epics/**/story-*.md) and Game Design Documents (GDDs). Malicious instructions embedded in these files could theoretically influence the agent's output during the plan generation phase. - Ingestion points: Story files (
production/epics/), GDD files (design/gdd/), and sprint plans (production/sprints/). - Boundary markers: None explicitly defined for isolating the content of the
Acceptance CriteriaorEngine notessections during processing. - Capability inventory: The skill has access to
Write,Edit, and limitedBashcapabilities, which are used to generate the final QA plan and back-fill test cases into story files. - Sanitization: No specific sanitization or escaping of external content is mentioned before it is interpolated into the test plan templates.
Audit Metadata