adr-drafting

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads existing ADR files in the repository to infer conventions, which presents an indirect prompt injection surface.
  • Ingestion points: In Phase 2, the skill reads up to three existing ADR examples from the repository to infer numbering, naming, and style conventions.
  • Boundary markers: No explicit delimiters or instructions are used to separate the external content of the read ADRs from the agent's internal reasoning or generation instructions.
  • Capability inventory: The skill has file-system access via the Read, Write, Edit, and Glob tools to create new markdown documents.
  • Sanitization: No sanitization or validation is performed on the content retrieved from existing repository files before it is processed.
  • [SAFE]: No other security issues were detected. The skill uses standard documentation tools, follows professional instructional guidelines, and requires explicit user confirmation before performing write operations. No dangerous network calls or credential access patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:11 PM
Security Audit — agent-trust-hub — adr-drafting