team-enterprise-feature

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires running copilot --allow-all --max-autopilot-continues 50. This disables standard confirmation prompts for commands and allows for high-continuity automated operations, reducing human oversight.
  • [PROMPT_INJECTION]: An indirect prompt injection surface exists due to the chain of trust between sub-agents.
  • Ingestion points: Content is ingested from agent-generated files including docs/enterprise/scope.md, docs/enterprise/design-spec.md, and docs/enterprise/experiment-plan.md.
  • Boundary markers: Absent. The skill does not provide delimiters or instructions to treat ingested file content as potentially adversarial data.
  • Capability inventory: The workflow involves agents with implementation capabilities (eng-senior) taking instructions directly from files written by earlier agents in the pipeline.
  • Sanitization: Absent. There is no verification or cleaning of agent-generated output before it is used as input for subsequent tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:52 PM
Security Audit — agent-trust-hub — team-enterprise-feature