team-combat
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains no signs of data exfiltration, hardcoded credentials, or unauthorized network operations. Its stated purpose aligns with its requested tool permissions.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it is designed to ingest and process project-related files (such as design documents and source code) and act upon them using high-privilege tools like Bash and Task.
- Ingestion points: The skill reads content from
design/gdd/and project source files usingRead,Glob, andGrep. - Boundary markers: The instructions do not define clear delimiters or warnings to treat ingested file content as untrusted data.
- Capability inventory: The agent has access to
Bashfor shell execution,Write/Editfor file system modification, andTaskfor spawning autonomous subagents. - Sanitization: There are no instructions for sanitizing or validating the content of the design documents before they are passed to subagents or used to generate code.
Audit Metadata