solution-architect

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from project-level files.
  • Ingestion points: Phase 1 (Discovery) reads content from .forgewright/product-manager/BRD/brd.md and .forgewright/polymath/handoff/context-package.md to derive architecture constraints.
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands are used when interpolating this external data into the agent context.
  • Capability inventory: The skill possesses the capability to scaffold an entire project structure, including creating directories, writing source code, and generating Dockerfiles.
  • Sanitization: There is no evidence of validation or sanitization of the input data from the BRD or handoff documents before they are used to guide the architecture design process.
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection to load shared protocols and local configuration.
  • Evidence: Multiple !cat commands are used in the 'Protocols' and 'Engagement Mode' sections (e.g., !cat .production-grade.yaml).
  • Analysis: These commands are restricted to specific, relative paths within the skill or project directory. They do not accept user-supplied arguments or perform network operations, and are used for legitimate initialization of the skill's operating environment.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — solution-architect