skills/davidlee/doctrine/inquisition/Gen Agent Trust Hub

inquisition

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses role-play instructions to establish a specific adversarial persona ("Inquisitor"). It directs the agent to adopt a "menacing, fanatical zeal" and to "Presume guilt rather than innocence" when reviewing project artifacts. While these are strong behavioral directives, they are consistent with the skill's defined purpose of performing strict, adversarial reviews of doctrine and code conformity.
  • [PROMPT_INJECTION]: The skill includes an indirect prompt injection surface by reading external project files (e.g., README.md, CLAUDE.md, and files in .doctrine/) to establish "sanctioned doctrine."
  • Ingestion points: CLAUDE.md, AGENTS.md, README.md, .doctrine/adr/, .doctrine/spec/tech/, .doctrine/spec/product/, design.md, plan.toml, plan.md, slice-nnn.md.
  • Boundary markers: The skill does not define explicit delimiters to isolate content read from these files from the agent's internal instructions.
  • Capability inventory: The agent uses a custom doctrine CLI suite to manage review ledgers and verdicts.
  • Sanitization: No explicit sanitization or filtering of the content read from the doctrine files is performed before the agent processes it for the inquisition.
  • [COMMAND_EXECUTION]: The skill relies on several CLI tools (e.g., doctrine review, doctrine backlog, doctrine review prime) to perform its tasks. These commands are project-specific and appear to be part of the intended execution environment for managing the project's documentation and review lifecycle.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 02:07 PM
Security Audit — agent-trust-hub — inquisition