doc-bdd-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and validate untrusted artifact content (BDD documents) and project configuration data (.aidoc/profile.yaml). Maliciously crafted content within these audited files could attempt to influence the agent's logic or the downstream fixer skill.
  • Ingestion points: The skill reads BDD files from the docs/04_BDD/ directory and adaptation profile data from .aidoc/profile.yaml.
  • Boundary markers: The skill employs explicit instructions to de-anchor the audit lenses from author-provided scores and utilizes a ## Layer-specific playbook section to delimit trusted instructions from untrusted context.
  • Capability inventory: The skill performs file system operations (creating directories and writing audit/saga/verdict files) and invokes sub-agents (synthesizer) to process audit results. It also triggers external skills like doc-bdd-fixer based on findings.
  • Sanitization: Audit findings are merged and normalized by a dedicated synthesizer sub-agent, and a structural checklist based on a fixed template is used to enforce baseline document integrity.
  • [COMMAND_EXECUTION]: The skill uses shell commands via backticks to manage the execution lifecycle and track timeouts.
  • Evidence: The skill instructs the agent to use mkdir -p for directory management and date +%s combined with cat and arithmetic evaluation to implement a break-circuit mechanism for long-running audits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:02 AM
Security Audit — agent-trust-hub — doc-bdd-audit