story-readiness

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from story files, Architecture Decision Records (ADRs), and Game Design Documents (GDDs). Malicious instructions embedded in these files could potentially influence the agent's readiness verdict or subsequent actions.\n
  • Ingestion points: Markdown files located in production/epics/, docs/architecture/, design/gdd/, and production/sprints/ are read and interpreted by the agent.\n
  • Boundary markers: The instructions do not specify the use of delimiters or clear system-level instructions to ignore potential commands embedded within the data files.\n
  • Capability inventory: The agent can read arbitrary files, search the filesystem (Glob/Grep), ask user questions, and spawn sub-agents to perform further reviews.\n
  • Sanitization: There is no evidence of sanitization or escaping of the ingested content before it is processed by the model.\n- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes shell execution at load time via the ! syntax to resolve project configuration.\n
  • Evidence: The command !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config is executed when the skill is loaded.\n
  • Analysis: This command is used to resolve configuration settings (e.g., workflow tiers and testing strictness) from the environment. While the command is fixed and does not incorporate direct user input, it represents a high-privilege execution pattern at the skill's entry point.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — story-readiness