build
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill extracts and executes shell commands from the
Verify:field of plan files (e.g.,docs/plans/*.md). These commands are executed in an isolated worktree by both implementer and reviewer agents to validate changes. While this is the intended functionality, it relies on the safety of the input plan. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from markdown plan files. If these files are maliciously crafted or influenced by an attacker, they can contain dangerous shell commands in the
Verify:field that the skill will execute without further validation beyond the 'approved' status marker. - Ingestion points: Plan files located in
docs/plans/*.md, parsed byscripts/plan-steps.mjs. - Boundary markers: The skill requires the plan to have
status: approvedin its frontmatter, but does not provide runtime sanitization for the command strings themselves. - Capability inventory: The orchestration involves file writes, network-capable sub-agents, and arbitrary shell command execution via platform tools.
- Sanitization: None; the instructions explicitly state to run the command 'exactly as written'.
- [DYNAMIC_EXECUTION]: The skill dynamically dispatches tasks to sub-agents (Implementer, Reviewer, Guard) and manages 'peer' execution by spawning external CLI tools (
claude,codex) via scripts likescripts/peer-build.mjsandscripts/peer-run.mjs.
Audit Metadata