doc-chg-autopilot
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill explicitly instructs the agent to use the
--allow-skip-permissionsflag when executing thesaga_driver.pyscript. This flag is described as allowing the process to write files without the standard platform permission prompts, bypassing a key security constraint intended to ensure user oversight for file modifications. - [COMMAND_EXECUTION]: The workflow requires the execution of shell commands using the
Bashtool, specifically callingpython3on a script located at${CLAUDE_PLUGIN_ROOT}/tools/saga_driver.py. While the script is local to the plugin environment, the reliance on shell execution with elevated flags increases the risk profile. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data sources, including code diffs, incident references, and free-text change descriptions. This creates a vulnerability surface where malicious instructions embedded in those inputs could influence the agent's behavior during the automated CHG generation and audit phases.
- Ingestion points: Inputs defined in the 'Input Contract' section, including target paths, diffs, artifact lists, and incident references.
- Boundary markers: The instructions do not specify any delimiters or 'ignore' instructions to isolate untrusted input from the agent's primary directives.
- Capability inventory: The agent has the ability to execute shell commands (Bash), write files to the local file system (registry updates), and invoke other specialized sub-skills.
- Sanitization: There is no mention of sanitizing or validating the input data before it is used to populate templates or drive logic.
Recommendations
- AI detected serious security threats
Audit Metadata