plan-iterate
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes Git commands to generate diffs and verify file tracking within a repository context. Evidence:
scripts/package_phase_review.pycallssubprocess.runforgit ls-filesandgit diff. These calls are restricted to repository-relative paths with validation against directory traversal. - [INDIRECT_PROMPT_INJECTION]: The skill packages arbitrary artifacts and code diffs for external LLM review, creating an inherent attack surface for instructions embedded in untrusted data. 1. Ingestion points:
scripts/package_phase_review.pycollects data fromevidence_artifacts,progress_context_artifacts, andchanged_filesinto review ZIP bundles. 2. Boundary markers: Thetemplates/PHASE_REVIEW_REQUEST.mdtemplate instructs reviewers to prioritize deterministic evidence artifacts over prose implementation claims. 3. Capability inventory: The skill has file system access, ZIP creation, Git command execution inscripts/package_phase_review.py, and local Unix socket communication. 4. Sanitization: The system performs SHA-256 integrity verification inscripts/phase_status.pyand validates that all processed paths are relative and free of traversal characters.
Audit Metadata