review-team
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external content (SDD artifacts and peer persona slots), which creates a surface for indirect prompt injection attacks.
- Ingestion points: The skill reads the content of design artifacts and persona-output records stored as JSON files in the
.aidoc/review/directory. - Boundary markers: The instructions explicitly include a security policy stating that the artifact and peer slots are untrusted data and that subagents must never execute instructions found within them. It also directs agents to ignore author-provided self-assessment scores to prevent anchoring bias.
- Capability inventory: The skill utilizes file read/write operations within the project's runtime directory and manages the execution of subagents through the platform's Task mechanism.
- Sanitization: The skill references an internal
SECURITY_REVIEW.mdprotocol for handling untrusted input and uses structured JSON schemas (persona-output contract and saga journal) to limit the data format.
Audit Metadata