release-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a restricted
Bashtool to execute a local project script namedyaml-helper.sh. The tool definition in the skill's frontmatter limits the command to this specific script path to prevent arbitrary command execution. - [DYNAMIC_CONTEXT_INJECTION]: The skill employs the
!command syntax to run a shell command at the time the skill is loaded. Specifically, it executesbash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_configto retrieve project settings such as rigor levels and certification targets. This is used for legitimate project-specific configuration resolution. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by scanning source code files for comments (
TODO,FIXME,HACK) and including their content in the final checklist. - Ingestion points: Source files are read using the
GlobandGreptools. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the scanned code comments.
- Capability inventory: The skill has the ability to write files to the
production/releases/directory and execute a specific local bash script. - Sanitization: The skill does not perform sanitization or escaping of the scanned comment text before it is presented in the markdown report.
Audit Metadata