regression-suite

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and processes external design documents and bug reports which could contain malicious instructions designed to influence the agent's behavior during report generation.
  • Ingestion points: design/gdd/systems-index.md, production/qa/bugs/.md, tests/**/, production/qa/smoke-*.md.
  • Boundary markers: Absent. The skill does not define delimiters or specific instructions to ignore embedded commands in the source files.
  • Capability inventory: Read, Glob, Grep, Write, Edit, AskUserQuestion, Bash.
  • Sanitization: Absent. The skill does not mention escaping or sanitizing content extracted from external files before using it in the manifest or report.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the dynamic context injection syntax to execute a local helper script when the skill is loaded.
  • Pattern: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation,workflow,qa.level,system_overrides
  • Evidence: This command is used to populate configuration variables used throughout the skill's logic.
  • Context: The operation is a benign use of a local project-specific tool and is restricted by the allowed-tools policy defined in the skill's frontmatter.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — regression-suite