doubt-driven-development

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions and examples for executing external command-line tools to perform cross-model reviews. It specifically mentions tools like the Gemini CLI and Codex CLI.- [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary "artifacts" (such as code or text) and passes them to other AI models for review, creating a surface where malicious instructions embedded in an artifact could influence the reviewer's behavior.
  • Ingestion points: User-provided artifacts and contracts processed during the Step 2 (EXTRACT) and Step 3 (DOUBT) phases.
  • Boundary markers: The skill advises passing only the ARTIFACT and CONTRACT to the reviewer to minimize context leakage and suggests a hard mental separator in degraded self-questioning fallback scenarios.
  • Capability inventory: Shell execution capabilities using external command-line tools.
  • Sanitization: Instructions recommend using temporary files and stdin redirection to prevent shell injection from content within the artifacts.- [PROMPT_INJECTION]: The skill includes instructions intended to override the default behavior of sub-agents or personas, directing them to adopt an exclusively adversarial posture.
  • Evidence: The skill explicitly states that the adversarial prompt takes precedence over the persona's default response shape and provides a template instructing the reviewer to assume the author is overconfident and to skip validation or summarization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:26 AM
Security Audit — agent-trust-hub — doubt-driven-development