recipe-plan
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes the command
ls -la docs/design/*.md | head -10to list design documents for user selection. - [PROMPT_INJECTION]: Includes core identity and execution protocol instructions to define orchestrator behavior.
- [PROMPT_INJECTION]: Potential surface for indirect prompt injection via processed markdown files. Ingestion points: design documents read from docs/design/*.md in SKILL.md. Boundary markers: Absent in prompt interpolation. Capability inventory: Able to invoke sub-agents like acceptance-test-generator and work-planner in SKILL.md. Sanitization: No content filtering or validation mechanism detected.
Audit Metadata