doc-ears-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external EARS artifacts which are untrusted user-provided inputs.
- Ingestion points: Reads artifact content from project paths (e.g.,
docs/03_EARS/). - Boundary markers: The instructions explicitly label artifact paths as "untrusted content" and provide directives to subagents to "de-anchor" from author-provided scores to prevent manipulation.
- Capability inventory: Performs file writes to the
.aidoc/directory and dispatches subagents within theaidoc-flownamespace for specialized analysis. - Sanitization: Enforces strict structural templates and uses machine-readable JSON formats for results validation.
- [COMMAND_EXECUTION]: The skill uses
bashcommands to manage a local "saga" journal. These operations are limited to timestamping (date +%s), directory creation (mkdir), and reading state (cat), which are standard for tracking workflow state across sessions.
Audit Metadata