decision-doc-sync

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data to automate documentation updates, creating a risk that malicious instructions within source code could influence agent behavior or file content.
  • Ingestion points: The agent reads project source code and architecture decision record (ADR) files during the synchronization steps specified in SKILL.md.
  • Boundary markers: The instructions provide no specific delimiters or warnings to the agent to treat ingested code as data only or to ignore natural language commands found within processed files.
  • Capability inventory: The skill utilizes file-system write capabilities to modify or create README.md, DESIGN.md, AGENTS.md, and files within the docs/adr/ directory.
  • Sanitization: There are no verification, escaping, or validation mechanisms defined to sanitize the content extracted from the code before it is written to the documentation files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 02:03 AM
Security Audit — agent-trust-hub — decision-doc-sync