team-ui

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the exclamation-backtick syntax (!bash ...) to execute a shell script, yaml-helper.sh, during the skill's initialization phase. This command is used to resolve configuration keys such as review_mode, automation, and team.size from the project environment.
  • [PROMPT_INJECTION]: The instructions contain a "bounded exception" section that explicitly directs sub-agents to bypass the platform's standard Collaboration Protocol. It instructs agents to write to specific paths without asking for user approval, overriding the default requirement for manual confirmation of file modifications. While the scope is limited to new artifacts in specific directories, this is an intentional bypass of default safety and transparency controls.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to run the yaml-helper.sh script located in the project's hooks directory. This execution is used to bridge project-level configuration with the agent's runtime environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests content from several external project files, including design/gdd/game-concept.md, design/player-journey.md, and design/accessibility-requirements.md.
  • Ingestion points: Content from these files is read in Phase 1a and passed as distilled briefs to sub-agents like the ux-designer and ui-programmer in subsequent phases.
  • Boundary markers: The skill does not specify the use of delimiters or specific "ignore embedded instructions" warnings when passing this data to sub-agents.
  • Capability inventory: The skill has significant capabilities, including spawning sub-agents (Agent tool), executing shell commands (Bash tool), and writing files (Write/Edit tools).
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the content of these design documents before processing them, creating a surface where malicious instructions embedded in project documentation could influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — team-ui