team-audio
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes shell execution at load time via the
!syntax in Phase 0 to run a local script (yaml-helper.sh). The script is targeted using relative path traversal (../../), which accesses hooks outside the skill's own directory. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted design documents and asset lists, passing the distilled content to sub-agents, creating a vulnerability surface for embedded instructions. 1. Ingestion points:
SKILL.md(Step 2) reads design docs fromdesign/gdd/and asset lists fromassets/audio/. 2. Boundary markers: Absent; the skill does not use delimiters or instructions to ignore embedded commands in the ingested files. 3. Capability inventory: Orchestrator and sub-agents have access toWrite,Edit, andBashtools. 4. Sanitization: No sanitization or validation of the ingested document content is performed before interpolation. - [COMMAND_EXECUTION]: The skill requires the
Bashtool for configuration and technical implementation tasks. It explicitly directs sub-agents to bypass standard Collaboration Protocol write confirmations for artifacts inproduction/,docs/, andtests/directories, increasing the potential for autonomous unauthorized modifications.
Audit Metadata