team-live-ops
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic injection syntax to execute a configuration helper script at load time. Evidence:
!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,team.sizeinSKILL.md. The command is used for project-specific environment setup and configuration resolution. - [INDIRECT_PROMPT_INJECTION]: The skill ingests design and policy data from the workspace, creating a surface for potential instruction injection through external files. Ingestion points:
SKILL.mdinstructs the agent to readdesign/live-ops/economy-rules.mdanddesign/live-ops/ethics-policy.mdduring the economy design and review phases. Boundary markers (present): The skill implements "return contracts" for subagents to constrain their outputs and usesAskUserQuestionto gate phase transitions, ensuring user oversight. Capability inventory: The orchestration involves theAgent,Bash,Write, andEdittools as documented inSKILL.md. Sanitization (absent): The content from ingested files is passed to subagents without explicit sanitization or escaping. - [COMMAND_EXECUTION]: The skill relies on local shell script execution for operational configuration. Evidence: The skill calls a helper script (
yaml-helper.sh) located in a relativehooksdirectory to resolve runtime parameters. This script is restricted via the platform tool configuration.
Audit Metadata