information-architecture

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process untrusted data from the repository and user inputs.
  • Ingestion points: The agent is instructed to read repository files such as routes, navigation components, and existing documentation, and it also accepts user-provided data via $ARGUMENTS (SKILL.md).
  • Boundary markers: The instructions do not specify boundary markers or delimiters to isolate the analyzed content from the agent's instructions, nor do they instruct the agent to ignore instructions embedded in the source data.
  • Capability inventory: The agent has the capability to write the resulting analysis to the local file system (docs/hci/information-architecture.md) and create necessary directories.
  • Sanitization: No sanitization or validation of the ingested repository content or user arguments is mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:53 PM
Security Audit — agent-trust-hub — information-architecture