doc-chg-fixer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands within the workspace to handle directory initialization and track execution duration.
  • Evidence: Uses mkdir -p and date +%s to manage metadata in the .aidoc folder and enforce a 1500s soft deadline.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from audit reports and review slots, creating a vulnerability surface for instructions embedded in external data.
  • Ingestion points: Processes .aidoc/audit/09_CHG-audit.md and persona-specific review slots.
  • Boundary markers: No specific delimiters or warnings to ignore embedded instructions are mentioned for the ingested audit findings.
  • Capability inventory: The skill has permissions to read/write files and dispatch Task sub-agents (e.g., solutions-architect, security-engineer).
  • Sanitization: The skill relies on deterministic logic across eight fix phases (Phase 0–7) to modify CHG records rather than open-ended interpretation, which reduces risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:24 PM
Security Audit — agent-trust-hub — doc-chg-fixer