team-audio
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by ingesting project documentation and assets to instruct sub-agents. 1. Ingestion points: reads files from 'design/gdd/' and 'assets/audio/'. 2. Boundary markers: none present in instructions. 3. Capability inventory: uses 'Bash', 'Write', 'Task', and 'Edit' tools. 4. Sanitization: none performed on ingested content.
- [COMMAND_EXECUTION]: The skill uses the 'Bash' tool to implement audio systems and unit tests based on project context. This presents a risk of executing malicious code if context is poisoned, though the risk is mitigated by mandatory user approval steps using 'AskUserQuestion' before each transition.
Audit Metadata