doc-adr-audit
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (e.g.,
mkdir,date,cat) using an<ADR-id>variable derived from user-controlled input file paths. This creates a risk of command injection if the variable is not properly sanitized before being interpolated into shell instructions. Evidence:Bash: mkdir -p .aidoc/review/05_ADR/<ADR-id>/ && date +%s > .aidoc/review/05_ADR/<ADR-id>/.skill-start.auditand `Bash: echo $(( $(date +%s) - $(cat .aidoc/review/05_ADR//.skill-start.audit) ))
.- **[INDIRECT_PROMPT_INJECTION]:** The skill processes untrusted ADR files (docs/05_ADR/...) and passes them to subagents for analysis. While the skill includes instructions to disregard certain fields (e.g., author self-assessments), it lacks robust structural boundary markers to isolate untrusted data from the agent's instructions. Ingestion points: ADR file paths and content. Capability inventory: Shell execution viaBashblocks, file writing to the.aidoc/directory, and dispatching framework subagents. Sanitization: Absent during the data ingestion phase.- **[DYNAMIC_EXECUTION]:** The skill uses dynamic dispatch for subagents, mapping lens names (likearchitectorsecurity_engineer) to specific agent identifiers (e.g.,aidoc-flow:solutions-architect). These subagents are tasked with processing untrusted artifact content provided via absolute paths. Evidence: mapping logic in theteam modesection and the use ofsubagent_type` for task creation.
Recommendations
- AI detected serious security threats
Audit Metadata