spec-loop-write-adr
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown instructions and configuration files. No scripts, binaries, or automated shell commands are included.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data to generate documentation, which is a standard surface for indirect prompt injection.
- Ingestion points: Reads from task artifacts (Research, Analysis, Constraints, Design, Scenario) and user chat interactions.
- Boundary markers: No specific delimiters are defined for the input data.
- Capability inventory: The skill is restricted to drafting and updating markdown files in the
architecture-decisions/folder. - Sanitization: No explicit sanitization is performed on input data, but the 'Mandatory clarification gate' ensures the agent prompts the user for clarification on important decisions rather than proceeding autonomously.
Audit Metadata