architecture-decision
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests data from the local filesystem to gather context for new ADRs, which introduces an indirect prompt injection surface. Maliciously crafted content in source code or existing documentation could potentially manipulate the output generated by the agent.\n
- Ingestion points: The skill scans the
docs/architecture/directory and reads related project source code via theReadandGreptools.\n - Boundary markers: No specific delimiters or instructions (e.g., "ignore embedded instructions") are used when interpolating file content into the prompt context.\n
- Capability inventory: The skill is configured with
Read,Glob,Grep, andWritecapabilities, allowing it to modify files in the project documentation directory.\n - Sanitization: There is no evidence of sanitization, validation, or escaping of the content retrieved from the filesystem before it is processed by the model.
Audit Metadata