team-polish

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill executes a local configuration script ('yaml-helper.sh') using the exclamation-backtick syntax ('!bash ...') when the skill is loaded. This is used to resolve environment settings like review modes and team sizes. Evidence: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,team.size in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external feature descriptions and code files during the optimization phases. * Ingestion points: Feature/area descriptions and source files read by the performance-analyst and technical-artist (SKILL.md). * Boundary markers: The skill does not define explicit delimiters for untrusted data but utilizes a 'distilled brief' mechanism to sanitize context. * Capability inventory: Uses the 'Agent' tool to spawn sub-agents and the 'Bash' tool for profiling and config resolution. * Sanitization: The skill uses a distillation process to pass only necessary context to sub-agents.
  • [COMMAND_EXECUTION]: The skill uses the 'Bash' tool to run a local helper script and performance profiling tools. The usage is restricted to the local environment and project-specific tasks, and is further limited by tool-specific constraints in the skill frontmatter.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 09:44 AM
Security Audit — agent-trust-hub — team-polish