create-adr
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for Indirect Prompt Injection (Category 8).
- Ingestion points: The agent is instructed to read
docs/prd.mdanddocs/brief.mdto identify technical choices that need documenting (SKILL.md). - Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within these ingested files.
- Capability inventory: The agent has the capability to write architectural decisions to the repository (
docs/decisions/), which can influence the system's architecture and security controls (SKILL.md). - Sanitization: Input from project documents is not filtered or validated before being used to state the 'Rationale' or 'Decision' in generated artifacts.
- [PROMPT_INJECTION]: Massive context window bloat and deceptive technical content.
- The files
references/architecture-patterns.md,code-organization.md,deployment-pipelines.md,error-handling.md,performance-optimization.md,security-best-practices.md,state-management.md, andtesting-strategies.mdeach contain 150 repetitive sections of technical filler. - This filler text discusses kernel-space optimizations and eBPF in every file regardless of the file's stated topic (e.g., repeating the same kernel text in the testing and error-handling files).
- This pattern acts as a 'token-stuffing' or 'context-bloating' attack, which can displace safety instructions from the LLM's active context window, potentially increasing the risk of obedience to malicious instructions embedded in project documents.
- [PROMPT_INJECTION]: Social engineering in documentation.
- The reference files contain warnings that the content is 'strictly intended for Staff+ Engineers' and contains 'extremely dense technical specifications' (e.g., references/architecture-patterns.md). This language is designed to sound authoritative and discourage manual auditing of the bloated content.
Audit Metadata