team-ui
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the exclamation-backtick syntax (
!bash ...) to execute a shell script,yaml-helper.sh, during the skill's initialization phase. This command is used to resolve configuration keys such asreview_mode,automation, andteam.sizefrom the project environment. - [PROMPT_INJECTION]: The instructions contain a "bounded exception" section that explicitly directs sub-agents to bypass the platform's standard Collaboration Protocol. It instructs agents to write to specific paths without asking for user approval, overriding the default requirement for manual confirmation of file modifications. While the scope is limited to new artifacts in specific directories, this is an intentional bypass of default safety and transparency controls.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to run theyaml-helper.shscript located in the project's hooks directory. This execution is used to bridge project-level configuration with the agent's runtime environment. - [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests content from several external project files, including
design/gdd/game-concept.md,design/player-journey.md, anddesign/accessibility-requirements.md. - Ingestion points: Content from these files is read in Phase 1a and passed as distilled briefs to sub-agents like the
ux-designerandui-programmerin subsequent phases. - Boundary markers: The skill does not specify the use of delimiters or specific "ignore embedded instructions" warnings when passing this data to sub-agents.
- Capability inventory: The skill has significant capabilities, including spawning sub-agents (
Agenttool), executing shell commands (Bashtool), and writing files (Write/Edittools). - Sanitization: There are no explicit instructions for the agent to sanitize or validate the content of these design documents before processing them, creating a surface where malicious instructions embedded in project documentation could influence agent behavior.
Audit Metadata