adr-writing
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a bundled Python script (
scripts/next_adr_number.py) to calculate the next sequence number for ADR files. This script uses standard Python libraries to scan the local directory structure and does not perform network operations or access sensitive system files. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest external data (source code and existing documentation) to gather context for writing decisions. This creates a surface for indirect prompt injection if the project files contain malicious directives.
- Ingestion points: Reads related implementation code and existing ADR documents in
docs/adrs/during the 'Explore Context' step. - Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions found within the ingested project files.
- Capability inventory: The skill can execute local scripts and write new Markdown files to the workspace.
- Sanitization: There are no explicit steps provided to sanitize or escape data extracted from external files before it is used to generate the new ADR content.
Audit Metadata