team-combat

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMPROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the exclamation-backtick syntax (!bash) to execute a local shell script (yaml-helper.sh) at skill load time. This execution happens before the AI agent processes the content and relies on the presence and integrity of scripts located in the ${CLAUDE_SKILL_DIR}/../../hooks/ directory.
  • [PROMPT_INJECTION]: The instructions include a specific command to bypass safety guidelines, referred to as a "bounded exception." It directs sub-agents to perform file writes without the standard user confirmation prompt required by the "Collaboration Protocol" (e.g., "Write your full output to [path]... write it without a separate approval prompt"). This is an intentional instruction to override the agent's safety constraints.
  • [PRIVILEGE_ESCALATION]: By commanding agents to skip the "May I write this to [filepath]?" prompt, the skill attempts to grant sub-agents higher autonomy and write privileges than the platform's default safety configuration allows.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface for indirect prompt injection due to its complex multi-agent orchestration.
  • Ingestion points: User-provided [combat feature description], output from sub-agents (GDDs, architecture sketches, and test cases) which are read and processed in later phases.
  • Boundary markers: The skill lacks clear delimiters or instructions for sub-agents to ignore potentially malicious content within the design artifacts they process.
  • Capability inventory: The skill uses Agent spawning, Bash execution, and Write/Edit tools (delegated to sub-agents).
  • Sanitization: There is no evident sanitization of the content generated by one sub-agent before it is used as a prompt brief for another sub-agent.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to run configuration resolution scripts. While these appear to be internal hooks, the use of shell execution at load time increases the skill's risk profile.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — team-combat