doc-tdd-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided Technical Design Documents (TDDs), which are untrusted external inputs. These documents could contain malicious instructions or specially crafted metadata fields intended to manipulate the auditing subagents or the primary agent's execution flow.
  • Ingestion points: Technical Design Document files located at user-defined paths (e.g., docs/07_TDD/TDD-NN_*/...) and their internal content.
  • Boundary markers: The skill includes specific instructions to "disregard the author self-assessment score" to prevent anchoring bias in subagents, but it lacks comprehensive structural delimiters or clear "ignore embedded instructions" warnings for the entirety of the processed artifact.
  • Capability inventory: The skill utilizes shell command execution via Bash: blocks, performs file system writes (e.g., overwriting .aidoc/audit/07_TDD-audit.md), and dispatches multiple autonomous Task subagents.
  • Sanitization: There are no explicit instructions or regex patterns provided to sanitize or validate data extracted from the TDDs (such as the artifact ID) before that data is used in subsequent operations.
  • [COMMAND_EXECUTION]: The skill workflow includes multiple shell commands described in Bash: blocks for managing the state of an audit "Saga."
  • Evidence: The skill instructs the agent to execute commands such as mkdir -p .aidoc/review/07_TDD/<TDD-id>/ && date +%s > .aidoc/review/07_TDD/<TDD-id>/.skill-start.audit and `echo $(( $(date +%s)
  • $(cat .aidoc/review/07_TDD//.skill-start.audit) ))`.
  • Risk: These commands interpolate the <TDD-id> variable, which is extracted directly from the artifact being audited. If an attacker provides a TDD with a malicious ID (e.g., containing shell metacharacters like ;, &, or backticks), it could result in arbitrary command execution on the host environment when the audit is initiated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:58 PM
Security Audit — agent-trust-hub — doc-tdd-audit