solution-architect
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from project-level files.
- Ingestion points: Phase 1 (Discovery) reads content from
.forgewright/product-manager/BRD/brd.mdand.forgewright/polymath/handoff/context-package.mdto derive architecture constraints. - Boundary markers: No specific boundary markers or instructions to ignore embedded commands are used when interpolating this external data into the agent context.
- Capability inventory: The skill possesses the capability to scaffold an entire project structure, including creating directories, writing source code, and generating Dockerfiles.
- Sanitization: There is no evidence of validation or sanitization of the input data from the BRD or handoff documents before they are used to guide the architecture design process.
- [COMMAND_EXECUTION]: The skill utilizes dynamic context injection to load shared protocols and local configuration.
- Evidence: Multiple
!catcommands are used in the 'Protocols' and 'Engagement Mode' sections (e.g.,!cat .production-grade.yaml). - Analysis: These commands are restricted to specific, relative paths within the skill or project directory. They do not accept user-supplied arguments or perform network operations, and are used for legitimate initialization of the skill's operating environment.
Audit Metadata