data-forms
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs anchoring directives such as "execute it exactly as written" and "authoritative playbook" to influence agent prioritization and potentially override safety guardrails.
- [PROMPT_INJECTION]: The skill ingests instructions from external project paths, creating a vulnerability surface for indirect prompt injection. Ingestion points:
.claude/skills/data-forms/SKILL.mdand.agents/rules/cog.md. Boundary markers: None detected. Capability inventory: Usesinvoke_subagentfor task delegation. Sanitization: No validation or sanitization of the external file content is performed before processing. - [REMOTE_CODE_EXECUTION]: The skill implements dynamic path resolution (the "Antigravity substitution") where it constructs subagent paths based on names provided in playbook files. Dynamic loading from computed paths is a potential vector for unintended code execution.
Audit Metadata