soak-test

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill executes a local shell script at load time to resolve configuration. Evidence: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation.
  • [COMMAND_EXECUTION]: Restricted shell access is granted to a project helper script (yaml-helper.sh) for resolving project configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files to generate the protocol. Ingestion points: project.yaml, game-concept.md, prior playtest findings. Capability inventory: Read, Write, Bash. Sanitization: None. Boundary markers: Absent. The risk is considered safe as the data sources are trusted project files and the output is a human-facing document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — soak-test