write-adr

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local commands including git, ls, and find to gather repository context and existing ADR numbering. It also calls a local Python script plugins/beagle-analysis/skills/adr-writing/scripts/next_adr_number.py. These operations are standard for development workflows and are scoped to the project directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes conversation history to extract architectural decisions, which is a potential surface for indirect prompt injection if the conversation contains malicious instructions.
  • Ingestion points: Conversation history analyzed during Step 2 (Extraction).
  • Boundary markers: The process enforces a specific JSON schema for extraction results as a structural gate.
  • Capability inventory: File writing to docs/adrs/, execution of repository-level discovery commands, and a local Python script.
  • Sanitization: A mandatory user confirmation step (Step 3) requires the user to review and manually select decisions before any ADR files are generated or scripts are run for numbering, serving as a robust mitigation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — write-adr