doc-ears-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands for utility tasks and process management.
- Evidence: It executes
mkdir,date, and shell arithmetic to track execution start times and calculate elapsed time for enforcing a soft deadline (break-circuit policy). - [INDIRECT_PROMPT_INJECTION]: The skill ingests external audit reports and review data which serve as the primary drivers for its remediation logic.
- Ingestion points: It reads structured audit findings from
.aidoc/audit/03_EARS-audit.mdand persona-specific review slots (JSON files) produced by other agents. - Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" markers for the content being processed.
- Capability inventory: The skill can read/write files in the local workspace, execute shell utilities, and dispatch internal subagents from the
aidoc-flownamespace. - Sanitization: No explicit sanitization or validation logic is defined for the content of the audit findings before they are used to influence agent dispatching or file patching.
Audit Metadata