tdd-migration-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the automated processing of external codebases, which presents a surface for instructions embedded in data.
- Ingestion points: External code enters the agent context from the
{source_path}and{reference_repo}variables, which are accessed by sub-agents such asscout,architect, andatlasacross various pipeline phases. - Boundary markers: There are no specific delimiters or instructions provided in the agent prompts to ensure that instructions embedded within the source files are ignored or treated as data.
- Capability inventory: The workflow utilizes the
Bash,Read, andTodoWritetools, providing the agents with the ability to modify the file system and execute shell commands. - Sanitization: The instructions do not define any validation or sanitization logic for content retrieved from the provided source paths or reference URLs before it is processed by the agents.
- [EXTERNAL_DOWNLOADS]: The skill allows the
REFERENCE_REPOparameter to be a URL. This leads to external network requests when theintegration-agent(e.g.,atlas) performs diff comparisons against the remote repository. - [COMMAND_EXECUTION]: The workflow uses the
Bashtool to run analysis and quality tools (tldr,qlty) on the target codebase. While these are intended for development, the execution of shell commands on external, potentially untrusted code constitutes a known attack surface.
Audit Metadata