migration-architect

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains well-documented Python scripts (migration_planner.py, compatibility_checker.py, rollback_generator.py) that use standard library modules to perform migration analysis. These scripts do not initiate network connections, access sensitive system files (e.g., SSH keys, cloud credentials), or perform hidden operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external JSON data which creates an ingestion surface for indirect prompt injection.
  • Ingestion points: User-supplied migration specifications and database/API schemas processed by the core scripts.
  • Boundary markers: Not present; the scripts parse raw JSON fields and interpolate values directly into generated text and JSON reports.
  • Capability inventory: The scripts are restricted to text processing and do not have capabilities to execute shell commands, perform network requests, or modify the file system outside of the specified output paths.
  • Sanitization: No specific sanitization of string values is performed beyond standard JSON parsing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:48 AM
Security Audit — agent-trust-hub — migration-architect