doc-chg-audit

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Change Management (CHG) records, which serves as a potential vector for indirect prompt injection if the record content contains malicious instructions designed to influence the auditor or subagents.
  • Ingestion points: The skill reads CHG records from paths like docs/governance/chg/.
  • Boundary markers: The instructions specify inlining content under ## Layer-specific playbook sections, which provides structural delimitation but lacks rigorous escaping of user-provided content.
  • Capability inventory: The skill can write files to the .aidoc/ directory, execute shell commands (date, cat, mkdir), and dispatch multiple subagents (Task) with elevated weights.
  • Sanitization: There is no explicit sanitization or filtering of the input artifact content mentioned, although it does include a specific instruction to disregard author-provided readiness scores (a mitigation against anchoring bias).
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for lifecycle management and performance monitoring.
  • Evidence: The skill uses Bash commands for saga management, such as mkdir -p for directory creation, date +%s for epoch timestamps, and cat for reading audit start times to implement circuit-breaking logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:20 PM
Security Audit — agent-trust-hub — doc-chg-audit