doc-ears-autopilot

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill mandates the execution of a Python script (saga_driver.py) located within the system's plugin root directory to drive the automation pipeline.
  • [PRIVILEGE_ESCALATION]: The skill instructs the agent to use the --allow-skip-permissions flag when invoking the automation driver. As documented in the skill, this flag intentionally bypasses standard user permission prompts for file writes, enabling unattended autonomous file system modifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by processing external data and executing commands.
  • Ingestion points: Reads content from PRDs, BRDs, IPLANs, and user prompts (SKILL.md).
  • Boundary markers: The skill lacks instructions for using delimiters or boundary markers to isolate untrusted input from the agent's logic.
  • Capability inventory: Perform file writes, update document indices, and execute shell commands via the Bash tool (SKILL.md).
  • Sanitization: There is no mention of sanitization or validation procedures for the ingested data before it influences the agent's workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 02:27 AM
Security Audit — agent-trust-hub — doc-ears-autopilot