smoke-check
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the local project environment to generate reports and determine build health.
- Ingestion points: The skill reads content from
project.yaml,production/qa/qa-plan-*.md, sprint plans, and automated test runner outputs (logs and XML results). - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat this ingested content as data rather than instructions, which could allow maliciously crafted project files to influence agent behavior.
- Capability inventory: The skill uses the
Bashtool to execute various commands and theWritetool to create report files. - Sanitization: There is no evidence of data sanitization or validation of the external inputs before they are interpolated into the agent's context.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes load-time shell execution to retrieve project configuration settings.
- Evidence: The skill uses the
!syntax to executeyaml-helper.shat load time:!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation,qa.level,testing.strict. - This represents a powerful mechanism that runs before the AI processes the skill body. In this case, it appears to be a legitimate use of project-specific tooling for configuration management.
Audit Metadata