build
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands that interpolate user-provided data directly into the command string. For example, the 'Setup' section uses a heredoc (
cat << EOF) to write to a configuration file, and the 'tldr-impact' section inserts a<target>variable into a CLI command. A malicious user can provide input containing shell metacharacters (e.g., backticks, $(), or 'EOF') to break out of the intended command and execute unauthorized shell code. - [DYNAMIC_EXECUTION]: The skill dynamically generates an orchestration state file (
orchestration.yaml) and session variables at runtime using string concatenation of user-controlled input like the feature description. This lack of sanitization in dynamically generated content is a primary vector for command and script injection attacks. - [INDIRECT_PROMPT_INJECTION]: The skill functions as an orchestrator that ingests untrusted data from the user and from the outputs of previous workflow phases, then interpolates this data into the system prompts for sub-agents (e.g., 'plan-agent' or 'implement_task'). There are no boundary markers or instructions for the sub-agents to ignore embedded commands within this data, exposing the workflow to potential hijacking.
- Ingestion points: The
descriptionargument of the/buildcommand and artifacts like specs or research documents produced during the workflow. - Boundary markers: The skill does not use delimiters or safety instructions when passing external content into sub-agent prompts.
- Capability inventory: The workflow has significant capabilities, including file creation (
cat), directory management (mkdir), and complex code implementation and git operations through sub-agents. - Sanitization: There is no evidence of validation or escaping of user input before it is used in prompts or shell commands.
Recommendations
- AI detected serious security threats
Audit Metadata