ask-silva
Warn
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill describes a
/wizardutility that generates interactive bash scripts to automate infrastructure provisioning, credential setup, and environment configuration. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a router for processing external and potentially untrusted data, such as bug reports and feature requests, which can influence subsequent engineering actions.
- Ingestion points: Bug reports, incoming feature requests, and external project documentation processed via the
/triageand/grill-with-docsworkflows as described in SKILL.md. - Boundary markers: The instructions mention "context hygiene" and the use of
/compactfor summarization, but they do not define specific delimiters or instructions to ignore embedded commands in external data. - Capability inventory: The orchestration flow utilizes tools with significant system capabilities, including file creation and modification (
/to-spec,/to-tickets,/implement), test execution (/tdd), and merge conflict resolution. - Sanitization: There is no evidence of content sanitization or validation for the data ingested during the triaging or discovery phases.
- [COMMAND_EXECUTION]: The skill documentation includes instructions for executing various system and workflow commands, including a mandatory
/setup-matt-pocock-skillsprecondition.
Audit Metadata