team-qa

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local script 'yaml-helper.sh' to resolve project configuration parameters. This tool usage is restricted by a specific tool-call pattern in the skill's frontmatter.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the '!' command syntax to execute a shell script at load time for configuration resolution. The target is a local project hook file.
  • [PROMPT_INJECTION]: The instructions include a specific directive for subagents to bypass standard user-approval prompts when writing files to specific project directories like 'production/' and 'tests/'. This is an intentional override of platform safety protocols for file modifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted story and sprint data which creates a surface for indirect prompt injection. 1. Ingestion points: Sprint files and story files are read in Phase 1 and 2 (SKILL.md). 2. Boundary markers: The prompts for subagents do not define delimiters or instructions to ignore embedded directives in the ingested content. 3. Capability inventory: The main agent and subagents have the ability to write files and spawn sub-agents (SKILL.md). 4. Sanitization: No sanitization is performed on the ingested content before it is processed by subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — team-qa