skills/davidlee/doctrine/inquisition/Gen Agent Trust Hub

inquisition

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill mandates a 'menacing, fanatical zealot' persona that includes metaphorical references to medieval punishments like 'burning at the stake.' This persona is used to frame a rigorous 'adversarial' review of project content, instructing the agent to 'presume guilt' when checking code and design documents.
  • [COMMAND_EXECUTION]: The skill relies on a suite of 'doctrine' CLI commands (e.g., 'doctrine review prime', 'doctrine review raise', 'doctrine backlog new') to manage the review lifecycle and interact with project data. These commands are presented as the standard interface for the skill's state management.
  • [SAFE]: All operations are confined to the local project environment, targeting files such as 'CLAUDE.md', 'README.md', and the '.doctrine/' directory. No evidence of data exfiltration, remote downloads, or credential harvesting was found.
  • [SAFE]: The skill inherently processes external data (the code and documentation being reviewed), which is a common indirect prompt injection surface. However, it follows a structured procedure using local files as the authoritative 'doctrine' to mitigate accidental behavior changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:12 PM
Security Audit — agent-trust-hub — inquisition