doc-adr-autopilot

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a Python script (saga_driver.py) using the Bash tool from a path defined by the ${CLAUDE_PLUGIN_ROOT} environment variable.
  • [PRIVILEGE_ESCALATION]: The instructions explicitly mandate the use of the --allow-skip-permissions flag during script execution. This flag is designed to bypass standard user permission prompts for file-writing tasks, which significantly reduces the human-in-the-loop safety oversight of the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes various untrusted external documents (BRD, PRD, EARS, BDD) to generate new content, creating a vulnerability to indirect prompt injection.
  • Ingestion points: Processes BRD, PRD, EARS, BDD artifacts, user prompts, and IPLAN files (SKILL.md).
  • Boundary markers: No delimiters or 'ignore' instructions are present to separate untrusted data from the agent's instructions.
  • Capability inventory: Includes shell command execution (Bash) and local file writing.
  • Sanitization: No evidence of input sanitization or validation was found in the skill instructions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 17, 2026, 01:21 AM
Security Audit — agent-trust-hub — doc-adr-autopilot