doc-spec-autopilot
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions mandate the use of the Bash tool to execute a local Python script:
python3 "${CLAUDE_PLUGIN_ROOT}/tools/saga_driver.py" --layer 06_SPEC --allow-skip-permissions. - [PRIVILEGE_ESCALATION]: The workflow explicitly utilizes the
--allow-skip-permissionsflag. The skill's documentation confirms this is intended to bypass standard permission prompts for file writes, enabling "unattended autopilot" which removes user oversight from potentially dangerous file system operations. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data which could contain malicious instructions.
- Ingestion points: The skill reads BDD/ADR documents, implementation plans (IPLAN), and free-text user prompts as primary sources for specification generation.
- Boundary markers: No explicit boundary markers or instructions to ignore embedded commands within the source documents are provided in the workflow.
- Capability inventory: The skill has access to the
Bashtool and file system write capabilities via thesaga_driver.pyscript and thedoc-spec-fixerdependency. - Sanitization: There is no evidence of sanitization or validation performed on the content of the upstream artifacts before they are interpolated into the generation and audit logic.
Recommendations
- AI detected serious security threats
Audit Metadata