team-live-ops

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic injection syntax to execute a configuration helper script at load time. Evidence: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,team.size in SKILL.md. The command is used for project-specific environment setup and configuration resolution.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests design and policy data from the workspace, creating a surface for potential instruction injection through external files. Ingestion points: SKILL.md instructs the agent to read design/live-ops/economy-rules.md and design/live-ops/ethics-policy.md during the economy design and review phases. Boundary markers (present): The skill implements "return contracts" for subagents to constrain their outputs and uses AskUserQuestion to gate phase transitions, ensuring user oversight. Capability inventory: The orchestration involves the Agent, Bash, Write, and Edit tools as documented in SKILL.md. Sanitization (absent): The content from ingested files is passed to subagents without explicit sanitization or escaping.
  • [COMMAND_EXECUTION]: The skill relies on local shell script execution for operational configuration. Evidence: The skill calls a helper script (yaml-helper.sh) located in a relative hooks directory to resolve runtime parameters. This script is restricted via the platform tool configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — team-live-ops