artifact-review

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions to 'Ignore Claude-specific mode-switch instructions when they appear'. Although framed as a compatibility note for different AI environments, this pattern involves instructing the agent to disregard certain platform-level directives.
  • [COMMAND_EXECUTION]: The skill utilizes high-privilege platform capabilities, including spawning sub-agents (spawn_agent) and executing local scripts (e.g., python .claude/scripts/code_graph). While these are integrated into the intended workflow, they represent an execution surface within the agent's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is specifically designed to ingest and analyze external artifacts which are not under the skill's control, creating a vulnerability surface.
  • Ingestion points: Documentation files such as PBIs, user stories, design specifications, and test specifications (referenced via relative paths or CLI arguments).
  • Boundary markers: None explicitly defined in the provided instructions to isolate untrusted content from the system prompt.
  • Capability inventory: The agent has access to spawn_agent for task delegation and python for code graph analysis.
  • Sanitization: The instructions do not specify any validation, filtering, or escaping techniques for the text contained within the analyzed artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — artifact-review