architecture-decision-record
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes local repository files to extract context and calculate ADR sequences, creating a surface for indirect prompt injection.
- Ingestion points: Repository files are accessed via the Read, Glob, and Grep tools, and file metadata is retrieved using shell commands like ls.
- Boundary markers: The instructions lack explicit delimiters or safety directives to ignore potentially malicious instructions embedded within the files being analyzed.
- Capability inventory: The agent can write new files and modify existing ones based on the processed content.
- Sanitization: User-supplied arguments and repository file content are interpolated directly into markdown templates without evident sanitization.
- [COMMAND_EXECUTION]: The Python utility script adr-manager.py uses the subprocess module to execute system commands.
- Evidence: The script calls subprocess.run(['git', 'config', 'user.name'], ...) to identify the document author.
- Context: This is a benign use of shell interaction to retrieve project metadata and does not process untrusted input.
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses platform-specific syntax to execute shell commands at load time for auto-populating document fields.
- Evidence: SKILL.md and scripts/create-adr.md contain commands like !date and !git config to fill template values.
- Context: The commands are static, relate to standard project metadata, and do not involve sensitive file access or network exfiltration.
Audit Metadata