doc-bdd-fixer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for BDD document remediation and does not exhibit any malicious behavior. It follows established project workflows and utilizes internal framework resources.
  • [COMMAND_EXECUTION]: The skill uses basic shell commands (mkdir, date, cat) to manage session metadata and track performance deadlines. These operations are restricted to project-local paths (e.g., .aidoc/review/) and do not pose a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface as it reads audit findings from .aidoc/audit/04_BDD-audit.md and related JSON slots.
  • Ingestion points: Data enters via audit reports and persona-specific review slots in the .aidoc/ directory.
  • Boundary markers: None explicitly defined in the instructions for parsing external content.
  • Capability inventory: The skill can create directories, write markdown/YAML files, and move files within the project structure.
  • Sanitization: Not explicitly mentioned; however, the output is restricted to documentation fixes (formatting, template insertion, and link updates) which limits the impact of potential injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:03 AM
Security Audit — agent-trust-hub — doc-bdd-fixer