smoke-check

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the local project environment to generate reports and determine build health.
  • Ingestion points: The skill reads content from project.yaml, production/qa/qa-plan-*.md, sprint plans, and automated test runner outputs (logs and XML results).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat this ingested content as data rather than instructions, which could allow maliciously crafted project files to influence agent behavior.
  • Capability inventory: The skill uses the Bash tool to execute various commands and the Write tool to create report files.
  • Sanitization: There is no evidence of data sanitization or validation of the external inputs before they are interpolated into the agent's context.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes load-time shell execution to retrieve project configuration settings.
  • Evidence: The skill uses the ! syntax to execute yaml-helper.sh at load time: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation,qa.level,testing.strict.
  • This represents a powerful mechanism that runs before the AI processes the skill body. In this case, it appears to be a legitimate use of project-specific tooling for configuration management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — smoke-check