project-discipline-guides
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/generate_mirrors.tsuseschild_process.spawnSyncto execute external CLI tools (gemini,claude, andcodex). This execution is a functional requirement to automate the generation of 'Knowledge Mirrors' from various AI models. The script follows safe practices by using argument arrays instead of shell strings to prevent command injection, and it allows configuration via environment variables. The use of specific flags like--dangerously-skip-permissions(for Claude Code) and--skip-trust(for Gemini) is consistent with non-interactive automation in a local developer environment.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes external technical guides. However, the risk is addressed through structured instructions and a specific logical framework for the agent to follow. - Ingestion points: The agent reads the 'Target' guide as part of the refactoring workflow in
SKILL.md. - Boundary markers: The skill does not use specific delimiters but provides a 'Strict A
- B Comparison' protocol to govern how the agent interprets the data.
- Capability inventory: The agent is empowered to perform file write operations ('Surgical Edits') on the target documentation files.
- Sanitization: There is no explicit sanitization of the guide content, but the workflow is inherently designed to reduce content rather than execute it.
Audit Metadata