doubt-driven-development

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill explicitly instructs the agent to use adversarial prompts that take precedence over and override the default response shape and instructions of sub-personas (e.g., code-reviewer). Specifically, it directs the user to 'Paste the adversarial prompt verbatim into the invocation so it overrides the persona's default.'
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands by instructing the agent to use which to check for binaries and then run external CLI tools such as gemini and codex. It provides specific command templates and instructions for piping data via stdin.
  • [REMOTE_CODE_EXECUTION]: The skill encourages the invocation of external AI command-line interfaces (Gemini CLI, Codex CLI) to perform cross-model reviews. This involves executing external binaries that send data to remote services.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to process 'artifacts' (which may be untrusted external code or data) and feed them into subagents or external tools. This creates an attack surface where a malicious artifact could contain prompt injections targeting the reviewer agent.
  • Ingestion points: Step 2 (EXTRACT) takes artifacts from the current workspace or user input.
  • Boundary markers: Uses structural markers like ARTIFACT: <paste artifact> and CONTRACT: <paste contract>.
  • Capability inventory: Subagent invocation, external shell command execution (via gemini/codex CLIs).
  • Sanitization: The skill recommends using stdin piping and read-only sandboxes to mitigate risks from embedded instructions in artifacts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — doubt-driven-development