spec
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses forceful instructional language such as 'MANDATORY IMPORTANT MUST CRITICAL' and 'NO EXCEPTIONS' to ensure strict adherence to its internal protocols. It also contains instructions to 'Ignore Claude-specific mode-switch instructions' and a self-authorizing clause for subagents: 'that skill activation authorizes use of the required spawn_agent subagent(s) for that task'.
- [COMMAND_EXECUTION]: The instructions direct the agent to perform multiple shell-based operations, including
grep,rg,find,git ls-files, andls -d, to scout the repository. It also calls for the execution of a local script,python .claude/scripts/code_graph, to trace code connections. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from the repository, such as source code and documentation, as well as user-provided requirements. This data is then used to generate feature specifications and test cases without explicit sanitization or instructions to ignore potentially malicious embedded content.
- Ingestion points: The skill reads repository source code and documentation via
grep,rg, andgitcommands described in the 'INIT' and 'UPDATE' modes inreferences/author.md. - Boundary markers: There are no explicit boundary markers or instructions to the agent to disregard instructions found within the ingested codebase files.
- Capability inventory: The skill possesses the capability to read files, execute shell commands, run local Python scripts, and write to the filesystem to update documentation.
- Sanitization: No specific sanitization, validation, or filtering of the ingested data is described before it is incorporated into the generated artifacts.
Audit Metadata