tech-debt

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is granted access to the Bash tool to perform configuration tasks. This access is explicitly restricted via the skill's frontmatter to a specific local script (yaml-helper.sh) located within the project's infrastructure hooks directory, preventing arbitrary command execution.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !command`` syntax at the top of SKILL.md to execute a shell command when the skill is loaded. This command (bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation) is used to fetch project-specific automation settings and is considered a legitimate use of project tooling.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an ingestion point for untrusted data by scanning source code files within the src/ directory for comments such as TODO, FIXME, and HACK.
  • Ingestion point: Codebase search findings processed in Phase 2A.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or provide warnings to the agent regarding potential instructions embedded within the code comments.
  • Capability inventory: The agent has access to Bash (restricted to the yaml-helper.sh script), Write (targeting the docs/tech-debt-register.md file), and AskUserQuestion.
  • Sanitization: The skill does not apply sanitization or filtering to the content of the comments before they are incorporated into the agent's context or written to the debt register.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — tech-debt