architecture-impact
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on generating architectural documentation and diagrams based on Pull Request data and codebase context. Its operations are limited to reading repository information and writing documentation files to the local directory.
- [COMMAND_EXECUTION]: The skill utilizes the
gh(GitHub CLI) tool to retrieve PR metadata (titles, bodies, comments, and reviews). This is a standard integration for analysis tools and uses validated input patterns (URL or PR number) to prevent command injection. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub PR descriptions and comments. While this presents a common surface for indirect prompt injection, the risk is mitigated as the skill's output is purely documentation-based and does not involve executing the ingested content as code.
- [DATA_EXPOSURE]: The skill reads the directory tree and local README/architecture files to gain context. This is necessary for its architectural analysis and the data remains within the agent's context for processing, with no evidence of exfiltration to external domains.
Audit Metadata