demo-guide
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions to 'Ignore Claude-specific mode-switch instructions when they appear', which is a behavior override. It also presents an attack surface for indirect prompt injection due to its core function of processing project data. Ingestion points: The agent ingests project configuration files, specs in 'docs/specs/', and source code from the repository. Boundary markers: The protocol uses an 'Understanding Brief' gate and requires mandatory 'file:line' citations for all evidence. Capability inventory: The skill can spawn subagents and execute local shell commands via Python. Sanitization: It implements a strict redaction rule for secrets ('redacted:…') but does not describe technical sanitization of ingested markdown or source code content.
- [COMMAND_EXECUTION]: The skill executes local scripts within the project directory, such as 'python .claude/scripts/code_graph', which is a standard pattern for the vendor's toolset but constitutes a shell command execution capability.
Audit Metadata