skills/davidlee/doctrine/dreaming/Gen Agent Trust Hub

dreaming

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it is designed to ingest and act upon data from external, potentially untrusted sources.
  • Ingestion points: The agent reads from an external memory corpus and processes content from cited sources such as code paths, documentation files, and Architecture Decision Records (ADRs) during the fact-checking and validation phases described in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions to distinguish external content from the agent's core logic, increasing the risk that the agent might follow instructions embedded within the data.
  • Capability inventory: The skill leverages the 'doctrine' command-line tool to perform actions like 'validate', 'edit', 'status', and 'link' on memory records, and it writes maintenance summaries to the local file system (e.g., 'notes.md').
  • Sanitization: There is no evidence of content filtering, escaping, or validation of the data retrieved from external files before it is processed or incorporated into the memory system.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 03:03 AM
Security Audit — agent-trust-hub — dreaming