session-summary
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local script at
${PLUGIN_ROOT}/scripts/dae_resolve.pyto determine project scope. This is a local operation for path resolution. - [PROMPT_INJECTION]: Indirect prompt injection surface exists via data ingestion.
- Ingestion points: Reads from
handoffs/*.mdand conversation context (SKILL.md). - Boundary markers: Absent; no delimiters used for ingested content.
- Capability inventory: File system append and local script execution (SKILL.md).
- Sanitization: Absent; ingested content is not validated.
- [SAFE]: References a design document on Notion, a well-known service.
Audit Metadata