tdd-migration-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the automated processing of external codebases, which presents a surface for instructions embedded in data.
  • Ingestion points: External code enters the agent context from the {source_path} and {reference_repo} variables, which are accessed by sub-agents such as scout, architect, and atlas across various pipeline phases.
  • Boundary markers: There are no specific delimiters or instructions provided in the agent prompts to ensure that instructions embedded within the source files are ignored or treated as data.
  • Capability inventory: The workflow utilizes the Bash, Read, and TodoWrite tools, providing the agents with the ability to modify the file system and execute shell commands.
  • Sanitization: The instructions do not define any validation or sanitization logic for content retrieved from the provided source paths or reference URLs before it is processed by the agents.
  • [EXTERNAL_DOWNLOADS]: The skill allows the REFERENCE_REPO parameter to be a URL. This leads to external network requests when the integration-agent (e.g., atlas) performs diff comparisons against the remote repository.
  • [COMMAND_EXECUTION]: The workflow uses the Bash tool to run analysis and quality tools (tldr, qlty) on the target codebase. While these are intended for development, the execution of shell commands on external, potentially untrusted code constitutes a known attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — tdd-migration-pipeline