doc-iplan-autopilot
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to execute a Python script located at a path defined by an environment variable.
- Evidence:
python3 "${CLAUDE_PLUGIN_ROOT}/tools/saga_driver.py" --layer 08_IPLAN --allow-skip-permissions. - [PRIVILEGE_ESCALATION]: The instructions explicitly command the agent to use a specific flag to bypass platform-level safety and permission prompts for file system operations.
- Evidence: The prompt instructs the agent to run the driver with
--allow-skip-permissions, stating it "lets the phases the driver dispatches write files without a permission prompt — unattended autopilot requires it." - [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it processes untrusted upstream artifacts and external configuration files to drive automated logic.
- Ingestion points: Processes SPEC, TDD, and user prompts from the workspace, as well as configuration files like
.aidoc/profile.yamland.claude/aidoc-flow.config.yaml. - Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded instructions within the ingested SPEC or TDD files.
- Capability inventory: The skill utilizes the
Bashtool to perform extensive file modifications and index updates. - Sanitization: There is no evidence of sanitization or validation of the contents of the upstream artifacts before they are used to generate the IPLAN or influence the state machine.
Recommendations
- AI detected serious security threats
Audit Metadata