doc-adr-autopilot
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a Python script (saga_driver.py) using the Bash tool from a path defined by the ${CLAUDE_PLUGIN_ROOT} environment variable.
- [PRIVILEGE_ESCALATION]: The instructions explicitly mandate the use of the --allow-skip-permissions flag during script execution. This flag is designed to bypass standard user permission prompts for file-writing tasks, which significantly reduces the human-in-the-loop safety oversight of the agent.
- [INDIRECT_PROMPT_INJECTION]: The skill processes various untrusted external documents (BRD, PRD, EARS, BDD) to generate new content, creating a vulnerability to indirect prompt injection.
- Ingestion points: Processes BRD, PRD, EARS, BDD artifacts, user prompts, and IPLAN files (SKILL.md).
- Boundary markers: No delimiters or 'ignore' instructions are present to separate untrusted data from the agent's instructions.
- Capability inventory: Includes shell command execution (Bash) and local file writing.
- Sanitization: No evidence of input sanitization or validation was found in the skill instructions.
Recommendations
- AI detected serious security threats
Audit Metadata