doc-chg-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell commands within the workspace to handle directory initialization and track execution duration.
- Evidence: Uses
mkdir -panddate +%sto manage metadata in the.aidocfolder and enforce a 1500s soft deadline. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from audit reports and review slots, creating a vulnerability surface for instructions embedded in external data.
- Ingestion points: Processes
.aidoc/audit/09_CHG-audit.mdand persona-specific review slots. - Boundary markers: No specific delimiters or warnings to ignore embedded instructions are mentioned for the ingested audit findings.
- Capability inventory: The skill has permissions to read/write files and dispatch
Tasksub-agents (e.g.,solutions-architect,security-engineer). - Sanitization: The skill relies on deterministic logic across eight fix phases (Phase 0–7) to modify CHG records rather than open-ended interpretation, which reduces risk.
Audit Metadata