architecture-decision

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests data from the local filesystem to gather context for new ADRs, which introduces an indirect prompt injection surface. Maliciously crafted content in source code or existing documentation could potentially manipulate the output generated by the agent.\n
  • Ingestion points: The skill scans the docs/architecture/ directory and reads related project source code via the Read and Grep tools.\n
  • Boundary markers: No specific delimiters or instructions (e.g., "ignore embedded instructions") are used when interpolating file content into the prompt context.\n
  • Capability inventory: The skill is configured with Read, Glob, Grep, and Write capabilities, allowing it to modify files in the project documentation directory.\n
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the content retrieved from the filesystem before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — architecture-decision