parallel
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as an orchestrator that ingests data from subagents (code diffs, test results, and decision logs) and performs actions based on that data, which constitutes an inherent attack surface for indirect prompt injection.
- Ingestion points: Subagent reports, diffs, and decision logs defined in the
GATHERandRECONCILEphases ofSKILL.md. - Boundary markers: The skill enforces 'self-contained briefs' for subagents and a structured
unit report contract(YAML) to delimit information flow. - Capability inventory: The skill facilitates merging unit diffs onto integration branches and executing shell scripts such as
scripts/verify.sh. - Sanitization: The process includes human-in-the-loop triggers like the 'per-unit review gate' and a final 'combined adversarial review' to validate merged outputs.
- [COMMAND_EXECUTION]: The skill requires the agent to execute workspace-local scripts, specifically the stack skill's
scripts/verify.sh, to validate the merged state of parallel tasks. This is a functional requirement of the described TDD process and does not involve arbitrary or external command sources. - [EXTERNAL_DOWNLOADS]: The instructions reference model identifiers and routing logic retrieved from local configuration files such as
.rsc/developer.jsonand02-DOCS/wiki/sdd/config.yaml. These are used for platform-specific model selection and do not represent untrusted external downloads.
Audit Metadata