doc-adr-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes Architecture Decision Records (ADRs) and audit reports which may contain untrusted content. This content is interpolated into briefs for validation subagents like solutions-architect or security-engineer.
- Ingestion points: The skill reads
.aidoc/audit/05_ADR-audit.mdand various ADR files from the workspace (SKILL.md). - Boundary markers: Instructions do not define specific delimiters or instructions to prevent validation subagents from interpreting ingested document content as instructions.
- Capability inventory: The skill performs file system writes, creates backups in
tmp/backup/, and dispatches multiple subagent types to validate applied fixes. - Sanitization: No explicit sanitization or filtering of the ingested ADR content is mentioned before it is passed to the subagent validation loop.
- [COMMAND_EXECUTION]: The skill executes local bash commands to manage workflow timing and session state.
- Evidence: Uses
Bash: date +%sandBash: mkdir -pto initialize tracking files (.skill-start.fixer) and check for soft deadlines (1500s) to handle timeouts. - [DYNAMIC_EXECUTION]: The skill dynamically selects and dispatches subagents based on finding personas.
- Evidence: Maps lenses such as
architect,tech_lead, andchaos_engineerto specific subagent types (e.g.,aidoc-flow:solutions-architect) at runtime for parallel validation tasks.
Audit Metadata