adr-roadmap

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a prompt-based instructional file focused on analyzing architectural documentation. No evidence of prompt injection, data exfiltration, or obfuscation was found.
  • [SAFE]: The behavior described involves reading local markdown files and generating a summary file, which is typical for project management skills. It does not perform network operations or access sensitive system directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests ADR files which could theoretically contain malicious instructions. However, the ingestion surface is limited to structural data (ID, title, complexity, dependencies), and the skill enforces objective language and structural constraints, minimizing the risk of accidental instruction following.
  • [SAFE]: References to environment variables like ${CLAUDE_PLUGIN_ROOT} and other skills (e.g., charts-flow) are consistent with the platform's architectural layers and standards.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:15 AM
Security Audit — agent-trust-hub — adr-roadmap