story-done
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the
!bashsyntax in its YAML frontmatter and Phase 1 to execute a shell script at load time. The script is located at${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh, which involves path traversal to access a resource outside the skill's own directory. - [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands via the
Bashtool to verify acceptance criteria. Specifically, it runs test files mentioned within the story files. This creates a risk of arbitrary command execution if a story file is modified to point to a malicious script instead of a legitimate test. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources (story files, GDD documents, ADR records) and interpolates this data into prompts for other agents (
qa-lead,lead-programmer). 1. Ingestion points: Implementation story files (production/epics/**/*.md), architecture registries (docs/architecture/tr-registry.yaml), and design documents. 2. Boundary markers: The skill does not define clear delimiters or "ignore" instructions when passing extracted text to sub-agents. 3. Capability inventory: Includes fullBashaccess, file writing/editing (Write,Edit), and agent orchestration (Agent). 4. Sanitization: There is no evidence of sanitization or validation of the content extracted from external files before it is used to drive logic or influence agent behavior.
Audit Metadata