team-release

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEPROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that explicitly direct sub-agents to ignore the 'Collaboration Protocol' requirement for manual user approval before writing files. This 'bounded exception' allows sub-agents to write directly to specific paths in the production/, docs/, and tests/ directories, effectively overriding platform-level consistency guidelines for user confirmation.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic injection syntax (!) to execute a shell command at load time: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,team.size. This invokes a local utility script to populate configuration variables.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted local files to drive its logic, specifically reading from production/session-state/active.md and milestone files to infer the release version.
  • Ingestion points: Version inference logic in SKILL.md reads milestone and session state files.
  • Boundary markers: Employs AskUserQuestion to confirm the inferred version with the user before proceeding.
  • Capability inventory: Spawns sub-agents with Write, Edit, and Bash capabilities across the release pipeline.
  • Sanitization: No explicit sanitization or validation logic is present for the version string inferred from the project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — team-release