doc-bdd-autopilot
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill mandates the execution of a Python driver script (saga_driver.py) located within the framework's tools directory to manage its automation workflow.
- [PRIVILEGE_ESCALATION]: The workflow involves running a shell command with the --allow-skip-permissions flag. This flag is designed to suppress the agent's standard user confirmation prompts for file write actions, thereby bypassing a key security control in the agent's execution environment.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted requirements and prompts to generate BDD content. Ingestion points: Data is sourced from user prompts, EARS files in the docs/03_EARS/ directory, and implementation plans. Boundary markers: There are no specified delimiters or instructions to prevent the model from following instructions that might be embedded within the input data. Capability inventory: The skill has the ability to write files and execute framework scripts. Sanitization: The skill does not describe any methods for cleaning or validating the ingested content before it is used for document generation.
Audit Metadata