team-combat

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no signs of data exfiltration, hardcoded credentials, or unauthorized network operations. Its stated purpose aligns with its requested tool permissions.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it is designed to ingest and process project-related files (such as design documents and source code) and act upon them using high-privilege tools like Bash and Task.
  • Ingestion points: The skill reads content from design/gdd/ and project source files using Read, Glob, and Grep.
  • Boundary markers: The instructions do not define clear delimiters or warnings to treat ingested file content as untrusted data.
  • Capability inventory: The agent has access to Bash for shell execution, Write/Edit for file system modification, and Task for spawning autonomous subagents.
  • Sanitization: There are no instructions for sanitizing or validating the content of the design documents before they are passed to subagents or used to generate code.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — team-combat