review-all-gdds
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local shell script located at
.claude/scripts/review-scope.shusing theBashtool to determine which files have changed since the last review based on git history. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from various game design markdown files which creates a potential surface for indirect prompt injection. 1. Ingestion points: Files located in
design/gdd/*.mdanddesign/registry/entities.yaml. 2. Boundary markers: The skill does not use specific delimiters or instructions to ignore embedded commands when processing these files or passing them to sub-agents. 3. Capability inventory: The skill has access toBash(command execution),Write(file system modification), andAgent(sub-agent spawning). 4. Sanitization: There is no evidence of sanitization or validation of the markdown content before it is processed by the model or sub-agents. - [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!commandsyntax at load time to source.claude/hooks/yaml-helper.shand executeresolve_config. This is used for legitimate project-specific configuration loading.
Audit Metadata