trellis-continue
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script located at
./.trellis/scripts/get_context.pyusingpython3. This script is used to manage task state and retrieve workflow instructions. - [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data which serves as a potential attack surface for indirect prompt injection.
- Ingestion points: Data is ingested from
prd.md,implement.jsonl, and.trellis/workflow.mdwhen determining the current task status and next steps. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious embedded content within these files.
- Capability inventory: The skill has the capability to execute shell commands (
python3) based on the routing logic determined from the ingested files. - Sanitization: The skill does not describe any validation or sanitization of the contents within
prd.mdorimplement.jsonlbefore processing them.
Audit Metadata