doc-flow

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by scanning files in the docs/ directory and .aidoc/profile.yaml to determine project status and check for template conformance.
  • Ingestion points: Files located in docs/ and .aidoc/profile.yaml are read to identify active layers and document status.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the ingested file content.
  • Capability inventory: The skill is limited to reading files, reporting progress, and recommending other internal skills (e.g., doc-brd, doc-prd). It explicitly states it does not create artifacts itself.
  • Sanitization: The skill does not perform sanitization on the document content, but its primary function is structural validation (verifying headings) rather than processing logic from the text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:22 PM
Security Audit — agent-trust-hub — doc-flow