doc-chg-autopilot

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill explicitly instructs the agent to use the --allow-skip-permissions flag when executing the saga_driver.py script. This flag is described as allowing the process to write files without the standard platform permission prompts, bypassing a key security constraint intended to ensure user oversight for file modifications.
  • [COMMAND_EXECUTION]: The workflow requires the execution of shell commands using the Bash tool, specifically calling python3 on a script located at ${CLAUDE_PLUGIN_ROOT}/tools/saga_driver.py. While the script is local to the plugin environment, the reliance on shell execution with elevated flags increases the risk profile.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data sources, including code diffs, incident references, and free-text change descriptions. This creates a vulnerability surface where malicious instructions embedded in those inputs could influence the agent's behavior during the automated CHG generation and audit phases.
  • Ingestion points: Inputs defined in the 'Input Contract' section, including target paths, diffs, artifact lists, and incident references.
  • Boundary markers: The instructions do not specify any delimiters or 'ignore' instructions to isolate untrusted input from the agent's primary directives.
  • Capability inventory: The agent has the ability to execute shell commands (Bash), write files to the local file system (registry updates), and invoke other specialized sub-skills.
  • Sanitization: There is no mention of sanitizing or validating the input data before it is used to populate templates or drive logic.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 10:09 PM
Security Audit — agent-trust-hub — doc-chg-autopilot