project-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the project environment to determine framework behavior and architectural constraints, which could be exploited to influence the agent's actions if these files are compromised.
  • Ingestion points: The skill reads package.json, next.config.*, astro.config.*, and documentation files residing within node_modules/next/dist/docs/ (references/next.md).
  • Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore potential instructions embedded within the data it reads from the project files or documentation.
  • Capability inventory: The agent is authorized to modify UI components, layout structures, and component architecture, providing a significant impact surface if redirected.
  • Sanitization: There is no evidence of validation or filtering for the content read from the project's dependency manifests or installed documentation.
  • [DYNAMIC_EXECUTION]: The skill incorporates dynamic discovery mechanisms to load additional instructions (skills) based on the presence of specific files or directories in the project.
  • Evidence: The skill instructs the agent to discover and load additional logic from the .agents/skills/ directory (e.g., 'Astro skill' or 'Next.js workflow skills') and specific utility skills like shadcn-component-boundaries (SKILL.md, references/astro.md, references/next.md). This represents dynamic loading of executable instructions from computed local paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 02:03 AM
Security Audit — agent-trust-hub — project-architecture