java-architect
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and process existing codebases (domain models, service logic, project structures), which introduces a vulnerability surface where untrusted data could influence agent actions if it contains embedded instructions.
- Ingestion points: Architecture analysis, project review, and implementation steps described in SKILL.md.
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded prompts in analyzed code.
- Capability inventory: The skill has the ability to execute local shell commands for build verification (SKILL.md).
- Sanitization: No explicit sanitization or validation of the ingested codebase content is described prior to processing.
- [COMMAND_EXECUTION]: The workflow requires the execution of shell commands to verify implementation correctness and code quality.
- Evidence: Workflow steps in SKILL.md (steps 4, 5, and 6) explicitly instruct the use of
./mvnw verifyand./gradlew checkto run tests and security checks.
Audit Metadata