draft-adr

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input to generate documentation files, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: User answers to questions regarding architectural decisions in Step 1 and the output from a preceding plan-change command.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are used when interpolating these inputs into the ADR template.\n
  • Capability inventory: The skill utilizes ls and grep for discovery and has the capability to write Markdown files to the local file system (Step 5).\n
  • Sanitization: There is no evidence of input validation, escaping, or sanitization of the provided text before it is written to the ADR files.\n- [COMMAND_EXECUTION]: The skill uses shell commands to discover the project's ADR directory and naming convention.\n
  • Evidence: ls docs/decisions/ docs/adr/ docs/architecture/ .adr/ 2>/dev/null, ls docs/ | grep -iE 'adr|decision|architecture', and ls docs/decisions/ | sort | tail -5 in Step 2. These commands are restricted to local directory discovery and numbering.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — draft-adr