doc-adr-fixer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes Architecture Decision Records (ADRs) and audit reports which may contain untrusted content. This content is interpolated into briefs for validation subagents like solutions-architect or security-engineer.
  • Ingestion points: The skill reads .aidoc/audit/05_ADR-audit.md and various ADR files from the workspace (SKILL.md).
  • Boundary markers: Instructions do not define specific delimiters or instructions to prevent validation subagents from interpreting ingested document content as instructions.
  • Capability inventory: The skill performs file system writes, creates backups in tmp/backup/, and dispatches multiple subagent types to validate applied fixes.
  • Sanitization: No explicit sanitization or filtering of the ingested ADR content is mentioned before it is passed to the subagent validation loop.
  • [COMMAND_EXECUTION]: The skill executes local bash commands to manage workflow timing and session state.
  • Evidence: Uses Bash: date +%s and Bash: mkdir -p to initialize tracking files (.skill-start.fixer) and check for soft deadlines (1500s) to handle timeouts.
  • [DYNAMIC_EXECUTION]: The skill dynamically selects and dispatches subagents based on finding personas.
  • Evidence: Maps lenses such as architect, tech_lead, and chaos_engineer to specific subagent types (e.g., aidoc-flow:solutions-architect) at runtime for parallel validation tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:24 AM
Security Audit — agent-trust-hub — doc-adr-fixer