doc-chg-audit
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Change Management (CHG) records, which serves as a potential vector for indirect prompt injection if the record content contains malicious instructions designed to influence the auditor or subagents.
- Ingestion points: The skill reads CHG records from paths like
docs/governance/chg/. - Boundary markers: The instructions specify inlining content under
## Layer-specific playbooksections, which provides structural delimitation but lacks rigorous escaping of user-provided content. - Capability inventory: The skill can write files to the
.aidoc/directory, execute shell commands (date, cat, mkdir), and dispatch multiple subagents (Task) with elevated weights. - Sanitization: There is no explicit sanitization or filtering of the input artifact content mentioned, although it does include a specific instruction to disregard author-provided readiness scores (a mitigation against anchoring bias).
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for lifecycle management and performance monitoring.
- Evidence: The skill uses Bash commands for saga management, such as
mkdir -pfor directory creation,date +%sfor epoch timestamps, andcatfor reading audit start times to implement circuit-breaking logic.
Audit Metadata