doc-ears-fixer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands for utility tasks and process management.
  • Evidence: It executes mkdir, date, and shell arithmetic to track execution start times and calculate elapsed time for enforcing a soft deadline (break-circuit policy).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external audit reports and review data which serve as the primary drivers for its remediation logic.
  • Ingestion points: It reads structured audit findings from .aidoc/audit/03_EARS-audit.md and persona-specific review slots (JSON files) produced by other agents.
  • Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" markers for the content being processed.
  • Capability inventory: The skill can read/write files in the local workspace, execute shell utilities, and dispatch internal subagents from the aidoc-flow namespace.
  • Sanitization: No explicit sanitization or validation logic is defined for the content of the audit findings before they are used to influence agent dispatching or file patching.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:28 AM
Security Audit — agent-trust-hub — doc-ears-fixer