architecture-decision-record

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and processes local repository files to extract context and calculate ADR sequences, creating a surface for indirect prompt injection.
  • Ingestion points: Repository files are accessed via the Read, Glob, and Grep tools, and file metadata is retrieved using shell commands like ls.
  • Boundary markers: The instructions lack explicit delimiters or safety directives to ignore potentially malicious instructions embedded within the files being analyzed.
  • Capability inventory: The agent can write new files and modify existing ones based on the processed content.
  • Sanitization: User-supplied arguments and repository file content are interpolated directly into markdown templates without evident sanitization.
  • [COMMAND_EXECUTION]: The Python utility script adr-manager.py uses the subprocess module to execute system commands.
  • Evidence: The script calls subprocess.run(['git', 'config', 'user.name'], ...) to identify the document author.
  • Context: This is a benign use of shell interaction to retrieve project metadata and does not process untrusted input.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses platform-specific syntax to execute shell commands at load time for auto-populating document fields.
  • Evidence: SKILL.md and scripts/create-adr.md contain commands like !date and !git config to fill template values.
  • Context: The commands are static, relate to standard project metadata, and do not involve sensitive file access or network exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:15 PM
Security Audit — agent-trust-hub — architecture-decision-record