team-release
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEPROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions that explicitly direct sub-agents to ignore the 'Collaboration Protocol' requirement for manual user approval before writing files. This 'bounded exception' allows sub-agents to write directly to specific paths in the
production/,docs/, andtests/directories, effectively overriding platform-level consistency guidelines for user confirmation. - [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic injection syntax (
!) to execute a shell command at load time:!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,team.size. This invokes a local utility script to populate configuration variables. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted local files to drive its logic, specifically reading from
production/session-state/active.mdand milestone files to infer the release version. - Ingestion points: Version inference logic in
SKILL.mdreads milestone and session state files. - Boundary markers: Employs
AskUserQuestionto confirm the inferred version with the user before proceeding. - Capability inventory: Spawns sub-agents with
Write,Edit, andBashcapabilities across the release pipeline. - Sanitization: No explicit sanitization or validation logic is present for the version string inferred from the project files.
Audit Metadata