security-architecture-review
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists exclusively of markdown text and metadata. It does not include any executable scripts, configuration for external tools, or automation commands.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to evaluate external content such as software designs and pull requests, which could contain adversarial instructions. However, the lack of tool access or system-level capabilities within this skill effectively mitigates the risk of such injections.
- Ingestion points: Analyzes user-supplied design documents and pull requests.
- Boundary markers: The skill does not define specific delimiters for untrusted content.
- Capability inventory: No tools, network access, or file-writing capabilities are defined in the skill metadata or body.
- Sanitization: There are no automated sanitization steps as the skill is purely instructional.
Audit Metadata