skills/ruvnet/ruflo/adr-create/Gen Agent Trust Hub

adr-create

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell and filesystem tools (Bash, Write, Edit, Glob) to manage project documentation. These actions are aligned with the skill's stated purpose of ADR management.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a data ingestion surface where results from mcp__plugin_ruflo-core_ruflo__memory_search are incorporated into new ADR files. While no boundary markers or sanitization logic are defined to isolate this external content, no malicious behavior is directed.
  • [SAFE]: All database operations and memory search tools (mcp__plugin_ruflo-core_ruflo__agentdb_* and mcp__plugin_ruflo-core_ruflo__memory_*) are used within the context of the agent's environment for structured record keeping.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 06:38 AM
Security Audit — agent-trust-hub — adr-create