doc-tdd-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for directory management and process tracking. Specific examples include the use of
mkdirto create review directories and the use ofdateandcatwithin subshells to calculate elapsed time for the 'Saga' execution flow.\n- [DYNAMIC_EXECUTION]: The skill dynamically dispatches 'Task' subagents based on personas identified in the audit report (e.g.,test-architect,solutions-architect). This allows the agent to spawn specialized processes at runtime to validate specific portions of the document fixes.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes audit reports (.aidoc/audit/07_TDD-audit.md) which are generated from the content of TDD documents. If a TDD document were poisoned with malicious instructions, these could potentially be carried over into the audit report and subsequently ingested by the fixer skill during the remediation phase.\n - Ingestion points:
.aidoc/audit/07_TDD-audit.mdand persona-specific slots in.aidoc/review/07_TDD/.\n - Boundary markers: Not explicitly defined in the prompt instructions to isolate external data.\n
- Capability inventory: File read/write access, directory creation, and the ability to dispatch subagents with specific briefs.\n
- Sanitization: No explicit sanitization or filtering logic is provided for the content extracted from the audit reports before it is used to modify files or instruct subagents.
Audit Metadata