reverse-document
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax to execute a local shell command (yaml-helper.sh) during the initialization phase. This is used to resolve project configuration such as workflow tiers and automation modes. The command is restricted to a specific script and arguments defined in the allowed-tools metadata, ensuring it runs in a controlled execution environment.
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external codebases and prototypes which serves as an injection surface for instructions embedded in data. 1. Ingestion points: Phase 2 reads implementation details from user-provided paths using Read, Glob, and Grep tools. 2. Boundary markers: The skill does not define specific delimiters to wrap ingested code or ignore instructions within it. 3. Capability inventory: The skill utilizes Write, Edit, and Bash tools to perform its tasks. 4. Sanitization: No explicit sanitization or filtering of the source code is performed prior to analysis. The risk is mitigated by the collaborative workflow which requires the agent to present its findings and obtain explicit user approval before writing any documents to the filesystem.
Audit Metadata