doc-spec-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
Bashtool calls to perform local environment operations, specifically creating directories (mkdir -p) and generating Unix timestamps (date +%s) for session tracking and to implement a wall-clock timeout (break-circuit) mechanism. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external audit reports and persona review slots, which represents an indirect prompt injection surface.
- Ingestion points: The agent reads audit findings and recommendations from
.aidoc/audit/06_SPEC-audit.mdand various persona-specific review files located in.aidoc/review/06_SPEC/. - Boundary markers: There are no explicit boundary markers or instructions provided to the agent to treat the audit report data as untrusted or to ignore instructions potentially embedded within the findings.
- Capability inventory: The skill possesses significant capabilities, including extensive file system write/modify access to the project specifications, shell command execution via Bash, and the ability to dispatch
Tasksub-agents. - Sanitization: The instructions do not specify any sanitization, validation, or escaping logic for the content parsed from the audit reports before it is used to generate file patches or instructions for sub-agents.
Audit Metadata