trellis-meta
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various Python scripts located within the project's
.trellis/scripts/directory to manage task lifecycles, developer identity, and session context (e.g.,python3 ./.trellis/scripts/task.py current). - [DYNAMIC_EXECUTION]: The skill architecture relies on 'lifecycle hooks' defined in
.trellis/config.yamland platform-specific settings (like.claude/settings.json). These hooks allow the execution of arbitrary shell commands and scripts at specific project events (e.g.,after_create,after_finish), which the agent is encouraged to modify to customize behavior. - [INDIRECT_PROMPT_INJECTION]: The agent is designed to ingest and act upon data from untrusted local files, including Product Requirement Documents (
prd.md), technical designs (info.md), and engineering specifications (.trellis/spec/). - Ingestion points: The agent reads content from the
.trellis/tasks/and.trellis/spec/directories to determine implementation steps and quality rules. - Boundary markers: The system uses specific file manifests (
implement.jsonl,check.jsonl) to scope context, though it does not explicitly define safety delimiters for the content within those files. - Capability inventory: The agent has the capability to write files, execute shell commands, and modify the project's internal automation scripts.
- Sanitization: The skill does not describe specific sanitization steps for content read from project files before it is processed by the AI.
- [PERSISTENCE]: The use of lifecycle hooks in
config.yamland platform hooks in directories like.claude/hooks/provides a mechanism for code to be executed persistently across different development sessions based on project events.
Audit Metadata