artifact-review
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions to 'Ignore Claude-specific mode-switch instructions when they appear'. Although framed as a compatibility note for different AI environments, this pattern involves instructing the agent to disregard certain platform-level directives.
- [COMMAND_EXECUTION]: The skill utilizes high-privilege platform capabilities, including spawning sub-agents (
spawn_agent) and executing local scripts (e.g.,python .claude/scripts/code_graph). While these are integrated into the intended workflow, they represent an execution surface within the agent's environment. - [INDIRECT_PROMPT_INJECTION]: The skill is specifically designed to ingest and analyze external artifacts which are not under the skill's control, creating a vulnerability surface.
- Ingestion points: Documentation files such as PBIs, user stories, design specifications, and test specifications (referenced via relative paths or CLI arguments).
- Boundary markers: None explicitly defined in the provided instructions to isolate untrusted content from the system prompt.
- Capability inventory: The agent has access to
spawn_agentfor task delegation andpythonfor code graph analysis. - Sanitization: The instructions do not specify any validation, filtering, or escaping techniques for the text contained within the analyzed artifacts.
Audit Metadata