doubt-driven-development
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill explicitly instructs the agent to use adversarial prompts that take precedence over and override the default response shape and instructions of sub-personas (e.g., code-reviewer). Specifically, it directs the user to 'Paste the adversarial prompt verbatim into the invocation so it overrides the persona's default.'
- [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands by instructing the agent to use
whichto check for binaries and then run external CLI tools such asgeminiandcodex. It provides specific command templates and instructions for piping data via stdin. - [REMOTE_CODE_EXECUTION]: The skill encourages the invocation of external AI command-line interfaces (Gemini CLI, Codex CLI) to perform cross-model reviews. This involves executing external binaries that send data to remote services.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to process 'artifacts' (which may be untrusted external code or data) and feed them into subagents or external tools. This creates an attack surface where a malicious artifact could contain prompt injections targeting the reviewer agent.
- Ingestion points: Step 2 (EXTRACT) takes artifacts from the current workspace or user input.
- Boundary markers: Uses structural markers like
ARTIFACT: <paste artifact>andCONTRACT: <paste contract>. - Capability inventory: Subagent invocation, external shell command execution (via gemini/codex CLIs).
- Sanitization: The skill recommends using stdin piping and read-only sandboxes to mitigate risks from embedded instructions in artifacts.
Audit Metadata