draft-adr
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input to generate documentation files, creating a potential surface for indirect prompt injection.\n
- Ingestion points: User answers to questions regarding architectural decisions in Step 1 and the output from a preceding
plan-changecommand.\n - Boundary markers: No specific delimiters or instructions to ignore embedded commands are used when interpolating these inputs into the ADR template.\n
- Capability inventory: The skill utilizes
lsandgrepfor discovery and has the capability to write Markdown files to the local file system (Step 5).\n - Sanitization: There is no evidence of input validation, escaping, or sanitization of the provided text before it is written to the ADR files.\n- [COMMAND_EXECUTION]: The skill uses shell commands to discover the project's ADR directory and naming convention.\n
- Evidence:
ls docs/decisions/ docs/adr/ docs/architecture/ .adr/ 2>/dev/null,ls docs/ | grep -iE 'adr|decision|architecture', andls docs/decisions/ | sort | tail -5in Step 2. These commands are restricted to local directory discovery and numbering.
Audit Metadata