doc-brd-autopilot
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: In SKILL.md, the skill invokes the Bash tool to run a Python orchestration script (driver_saga.py) using the CLAUDE_PLUGIN_ROOT environment variable to define the path.
- [INDIRECT_PROMPT_INJECTION]: In SKILL.md, the skill is designed to ingest and process content from reference documents in the docs/00_REF/ directory. This creates an attack surface where malicious instructions hidden in the input data could attempt to influence the output or subvert the agent's instructions during the generation and audit cycle.
Audit Metadata