review-team

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external content (SDD artifacts and peer persona slots), which creates a surface for indirect prompt injection attacks.
  • Ingestion points: The skill reads the content of design artifacts and persona-output records stored as JSON files in the .aidoc/review/ directory.
  • Boundary markers: The instructions explicitly include a security policy stating that the artifact and peer slots are untrusted data and that subagents must never execute instructions found within them. It also directs agents to ignore author-provided self-assessment scores to prevent anchoring bias.
  • Capability inventory: The skill utilizes file read/write operations within the project's runtime directory and manages the execution of subagents through the platform's Task mechanism.
  • Sanitization: The skill references an internal SECURITY_REVIEW.md protocol for handling untrusted input and uses structured JSON schemas (persona-output contract and saga journal) to limit the data format.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 01:44 PM
Security Audit — agent-trust-hub — review-team