doc-ears-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external EARS artifacts which are untrusted user-provided inputs.
  • Ingestion points: Reads artifact content from project paths (e.g., docs/03_EARS/).
  • Boundary markers: The instructions explicitly label artifact paths as "untrusted content" and provide directives to subagents to "de-anchor" from author-provided scores to prevent manipulation.
  • Capability inventory: Performs file writes to the .aidoc/ directory and dispatches subagents within the aidoc-flow namespace for specialized analysis.
  • Sanitization: Enforces strict structural templates and uses machine-readable JSON formats for results validation.
  • [COMMAND_EXECUTION]: The skill uses bash commands to manage a local "saga" journal. These operations are limited to timestamping (date +%s), directory creation (mkdir), and reading state (cat), which are standard for tracking workflow state across sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:24 AM
Security Audit — agent-trust-hub — doc-ears-audit