team-audio

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by ingesting project documentation and assets to instruct sub-agents. 1. Ingestion points: reads files from 'design/gdd/' and 'assets/audio/'. 2. Boundary markers: none present in instructions. 3. Capability inventory: uses 'Bash', 'Write', 'Task', and 'Edit' tools. 4. Sanitization: none performed on ingested content.
  • [COMMAND_EXECUTION]: The skill uses the 'Bash' tool to implement audio systems and unit tests based on project context. This presents a risk of executing malicious code if context is poisoned, though the risk is mitigated by mandatory user approval steps using 'AskUserQuestion' before each transition.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 09:29 PM
Security Audit — agent-trust-hub — team-audio