review-all-gdds

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script located at .claude/scripts/review-scope.sh using the Bash tool to determine which files have changed since the last review based on git history.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from various game design markdown files which creates a potential surface for indirect prompt injection. 1. Ingestion points: Files located in design/gdd/*.md and design/registry/entities.yaml. 2. Boundary markers: The skill does not use specific delimiters or instructions to ignore embedded commands when processing these files or passing them to sub-agents. 3. Capability inventory: The skill has access to Bash (command execution), Write (file system modification), and Agent (sub-agent spawning). 4. Sanitization: There is no evidence of sanitization or validation of the markdown content before it is processed by the model or sub-agents.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the !command syntax at load time to source .claude/hooks/yaml-helper.sh and execute resolve_config. This is used for legitimate project-specific configuration loading.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:12 AM
Security Audit — agent-trust-hub — review-all-gdds