team-qa
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a local script 'yaml-helper.sh' to resolve project configuration parameters. This tool usage is restricted by a specific tool-call pattern in the skill's frontmatter.
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the '!' command syntax to execute a shell script at load time for configuration resolution. The target is a local project hook file.
- [PROMPT_INJECTION]: The instructions include a specific directive for subagents to bypass standard user-approval prompts when writing files to specific project directories like 'production/' and 'tests/'. This is an intentional override of platform safety protocols for file modifications.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted story and sprint data which creates a surface for indirect prompt injection. 1. Ingestion points: Sprint files and story files are read in Phase 1 and 2 (SKILL.md). 2. Boundary markers: The prompts for subagents do not define delimiters or instructions to ignore embedded directives in the ingested content. 3. Capability inventory: The main agent and subagents have the ability to write files and spawn sub-agents (SKILL.md). 4. Sanitization: No sanitization is performed on the ingested content before it is processed by subagents.
Audit Metadata