skills/joelhooks/joelclaw/adr-skill/Gen Agent Trust Hub

adr-skill

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data such as existing code, records, and instructions to generate documentation. While no malicious behavior was detected, this behavior creates a surface area for indirect prompt injection where malicious instructions embedded in the repository's files could influence the agent's output.
  • Ingestion points: The skill reads project instructions, decision indexes, and affected code as instructed in SKILL.md.
  • Boundary markers: The instructions do not define explicit boundaries or safety markers to distinguish between data and instructions within the ingested content.
  • Capability inventory: The skill possesses file-writing capabilities through its included scripts and can emit system events (system/adr.sync.requested).
  • Sanitization: There is no evidence of sanitization for data read from the repository before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill relies on local automation scripts to manage the ADR lifecycle. These scripts (scripts/bootstrap_adr.js, scripts/new_adr.js, scripts/set_adr_status.js) are used to initialize directories, generate files from templates, and update document status using standard Node.js file system modules. Additionally, the skill utilizes a CLI tool for searching records (joelclaw vault adr). All scripts and tools appear to be functional components provided by the skill author.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — adr-skill