decision-doc-sync
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data to automate documentation updates, creating a risk that malicious instructions within source code could influence agent behavior or file content.
- Ingestion points: The agent reads project source code and architecture decision record (ADR) files during the synchronization steps specified in
SKILL.md. - Boundary markers: The instructions provide no specific delimiters or warnings to the agent to treat ingested code as data only or to ignore natural language commands found within processed files.
- Capability inventory: The skill utilizes file-system write capabilities to modify or create
README.md,DESIGN.md,AGENTS.md, and files within thedocs/adr/directory. - Sanitization: There are no verification, escaping, or validation mechanisms defined to sanitize the content extracted from the code before it is written to the documentation files.
Audit Metadata