architecture-decision

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses a shell command execution (!bash) at the top of its SKILL.md file to resolve project-specific configuration keys like review_mode and workflow via a local script, yaml-helper.sh, located in the project's hooks directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the local file system, creating a potential attack surface for indirect prompt injection.
  • Ingestion points: The skill reads data from existing ADRs (docs/architecture/*.md), Design Documents (design/gdd/*.md), and Engine Reference files (docs/engine-reference/**).
  • Boundary markers: The instructions do not specify the use of clear delimiters or instructions to ignore embedded commands within the files being read.
  • Capability inventory: The skill has access to sensitive tools including file writing (Write, Edit), shell command execution (Bash), and subagent delegation (Agent).
  • Sanitization: There is no explicit mechanism described for sanitizing or validating the content read from files before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — architecture-decision