skills/davidlee/doctrine/reconcile/Gen Agent Trust Hub

reconcile

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using the doctrine CLI utility (revision, slice status) to manage project revisions and transitions based on input data.
  • [PROMPT_INJECTION]: This skill presents an indirect prompt injection surface as it ingests instructions from a markdown file (review-NNN.md) to determine the specific actions and parameters for its command execution and file writing tasks. * Ingestion points: Data is read from the ## Reconciliation Brief section of review-NNN.md. * Boundary markers: Relies on specific markdown section headers such as ## Reconciliation Brief and subheaders (### Per-slice, ### Governance/spec) to delimit instructions. * Capability inventory: The skill has the ability to execute doctrine CLI commands and perform direct write operations to local files like design.md and slice-NNN.md. * Sanitization: There is no explicit mechanism described to validate or sanitize the data extracted from the brief before it is interpolated into shell command flags such as --action, --target, or --to-status.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 07:20 AM
Security Audit — agent-trust-hub — reconcile