senior-architect
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project files to generate architecture diagrams and dependency reports. A malicious project could contain crafted strings in code comments or manifest files intended to influence the agent's reasoning when it reviews the analysis results.
- Ingestion points: The scripts
scripts/architecture_diagram_generator.py,scripts/dependency_analyzer.py, andscripts/project_architect.pyread source code and configuration files from the user-provided project directory. - Boundary markers: Analysis outputs are generated without explicit delimiters or safety instructions to distinguish analyzed data from the agent's core instructions.
- Capability inventory: The skill is limited to local file system reads and standard output; it does not perform network operations, execute arbitrary system commands, or write to sensitive system paths.
- Sanitization: Content extraction is performed via regular expressions which filter for specific patterns (like imports), but no sanitization is applied to the extracted text to prevent potential instruction injection.
Audit Metadata