skills/backnotprop/pstack/architect/Gen Agent Trust Hub

architect

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from existing codebases and user-provided tasks during the Grounding and Sketch phases. This presents a surface for indirect prompt injection where malicious instructions embedded in a project's source code could influence the agent's architectural decisions.
  • Ingestion points: Existing project subsystems analyzed in Phase A and grounding artifacts used in Phase B.
  • Boundary markers: The skill mentions 'boundary-discipline' as a principle, and Phase C provides an optional human checkpoint to review the synthesized design before implementation.
  • Capability inventory: The skill uses the 'arena' tool to orchestrate multiple sub-agents and generates file-based design artifacts like module maps and type sketches.
  • Sanitization: There is no evidence of explicit sanitization or filtering of the content ingested from the external environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 05:53 PM
Security Audit — agent-trust-hub — architect