create-adr

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions that attempt to override the agent's standard behavior and technical perspectives. Specifically, it mandates a specific database session management strategy and requires the agent to refer to the user by a specific name ("The Brougham 22").
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user descriptions to generate persistent files and commit messages, creating an injection surface. 1. Ingestion points: User-provided technical decisions and conversation history (SKILL.md). 2. Boundary markers: Absent; input is interpolated directly into templates. 3. Capability inventory: File system writes to /docs/adr/ and git commit execution (SKILL.md). 4. Sanitization: Absent; no validation or escaping is applied to the input.
  • [COMMAND_EXECUTION]: The skill requires the use of shell-level git commands to manage documentation history. 1. Evidence: Phase 3 instructions to stage and commit new files (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — create-adr