doc-brd-audit

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Business Requirements Documents (BRDs), which represents an attack surface for malicious instructions embedded in the analyzed data.
  • Ingestion points: The skill reads external artifact files from paths such as docs/01_BRD/BRD-NN_*/....
  • Boundary markers: The instructions explicitly label the input as "untrusted content" and provide structural templates to provide context. The skill instructs agents to "Disregard the author self-assessment score" to mitigate bias (de-anchoring).
  • Capability inventory: The skill possesses the ability to read and write local project files, execute local shell commands for state management, and dispatch sub-agents.
  • Sanitization: While the skill uses "de-anchoring" instructions to ignore specific metadata fields, it does not perform physical sanitization or filtering of the document prose before analysis.
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands to maintain an execution "saga" and enforce performance circuit-breakers.
  • Commands such as mkdir -p, date +%s, and cat are used to track session start times and results in the .aidoc directory.
  • An elapsed time check is performed using shell arithmetic to enforce a soft deadline of 1500 seconds, preventing hung processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:18 PM
Security Audit — agent-trust-hub — doc-brd-audit