backend-architecture
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
npxto run well-known API linting tools (@stoplight/spectral-cliand@redocly/cli) to validate generated OpenAPI specifications as part of the backend development workflow. - [EXTERNAL_DOWNLOADS]: The use of
npxfetches the specified linting tools from the official NPM registry (npmjs.com) if they are not already installed locally. These are well-known services provided by established vendors. - [PROMPT_INJECTION]: The skill processes external design documents, which presents a surface for indirect prompt injection. This is an inherent part of the skill's primary purpose to translate high-level designs into backend architecture.
- Ingestion points: Ingests content from
system-design.md, ADRs, and PRD sections as specified in Step 1 of the Process inSKILL.md. - Boundary markers: None; the skill does not specify markers to isolate untrusted input from the rest of the prompt context.
- Capability inventory: Executes shell commands via
npxfor contract validation as specified in Step 11 of the Process inSKILL.md. - Sanitization: None; the skill does not include steps to sanitize or validate the content of the input documents before processing.
Audit Metadata