team-enterprise-feature
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires running copilot --allow-all --max-autopilot-continues 50. This disables standard confirmation prompts for commands and allows for high-continuity automated operations, reducing human oversight.
- [PROMPT_INJECTION]: An indirect prompt injection surface exists due to the chain of trust between sub-agents.
- Ingestion points: Content is ingested from agent-generated files including docs/enterprise/scope.md, docs/enterprise/design-spec.md, and docs/enterprise/experiment-plan.md.
- Boundary markers: Absent. The skill does not provide delimiters or instructions to treat ingested file content as potentially adversarial data.
- Capability inventory: The workflow involves agents with implementation capabilities (eng-senior) taking instructions directly from files written by earlier agents in the pipeline.
- Sanitization: Absent. There is no verification or cleaning of agent-generated output before it is used as input for subsequent tasks.
Audit Metadata