solutions-architect
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is intended to process external architecture, workload, and migration data provided by users, creating a vector for indirect prompt injection if those files contain malicious instructions.\n
- Ingestion points: Untrusted data enters the agent context through file reads in scripts/architecture_scorer.py, scripts/migration_assessor.py, and scripts/sizing_calculator.py.\n
- Boundary markers: The skill does not include specific boundary markers or instructions to isolate processed data from the agent's primary task instructions.\n
- Capability inventory: The provided scripts are limited to file reading and mathematical reporting; they do not possess capabilities for network operations, dynamic code execution (eval/exec), or privilege escalation.\n
- Sanitization: The scripts use standard library parsers (json, csv) and include basic numeric and categorical validation for the data fields they process.
Audit Metadata