architect
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from existing codebases and user-provided tasks during the Grounding and Sketch phases. This presents a surface for indirect prompt injection where malicious instructions embedded in a project's source code could influence the agent's architectural decisions.
- Ingestion points: Existing project subsystems analyzed in Phase A and grounding artifacts used in Phase B.
- Boundary markers: The skill mentions 'boundary-discipline' as a principle, and Phase C provides an optional human checkpoint to review the synthesized design before implementation.
- Capability inventory: The skill uses the 'arena' tool to orchestrate multiple sub-agents and generates file-based design artifacts like module maps and type sketches.
- Sanitization: There is no evidence of explicit sanitization or filtering of the content ingested from the external environment.
Audit Metadata