story-done

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !bash syntax in its YAML frontmatter and Phase 1 to execute a shell script at load time. The script is located at ${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh, which involves path traversal to access a resource outside the skill's own directory.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands via the Bash tool to verify acceptance criteria. Specifically, it runs test files mentioned within the story files. This creates a risk of arbitrary command execution if a story file is modified to point to a malicious script instead of a legitimate test.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources (story files, GDD documents, ADR records) and interpolates this data into prompts for other agents (qa-lead, lead-programmer). 1. Ingestion points: Implementation story files (production/epics/**/*.md), architecture registries (docs/architecture/tr-registry.yaml), and design documents. 2. Boundary markers: The skill does not define clear delimiters or "ignore" instructions when passing extracted text to sub-agents. 3. Capability inventory: Includes full Bash access, file writing/editing (Write, Edit), and agent orchestration (Agent). 4. Sanitization: There is no evidence of sanitization or validation of the content extracted from external files before it is used to drive logic or influence agent behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — story-done