project-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the project environment to determine framework behavior and architectural constraints, which could be exploited to influence the agent's actions if these files are compromised.
- Ingestion points: The skill reads
package.json,next.config.*,astro.config.*, and documentation files residing withinnode_modules/next/dist/docs/(references/next.md). - Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore potential instructions embedded within the data it reads from the project files or documentation.
- Capability inventory: The agent is authorized to modify UI components, layout structures, and component architecture, providing a significant impact surface if redirected.
- Sanitization: There is no evidence of validation or filtering for the content read from the project's dependency manifests or installed documentation.
- [DYNAMIC_EXECUTION]: The skill incorporates dynamic discovery mechanisms to load additional instructions (skills) based on the presence of specific files or directories in the project.
- Evidence: The skill instructs the agent to discover and load additional logic from the
.agents/skills/directory (e.g., 'Astro skill' or 'Next.js workflow skills') and specific utility skills likeshadcn-component-boundaries(SKILL.md, references/astro.md, references/next.md). This represents dynamic loading of executable instructions from computed local paths.
Audit Metadata