senior-architect

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external project data via the target path arguments in its analysis scripts, creating an inherent attack surface for indirect prompt injection.\n
  • Ingestion points: Source code, configuration files, and project metadata within the directory specified by the target_path parameter in scripts/project_architect.py, scripts/architecture_diagram_generator.py, and scripts/dependency_analyzer.py.\n
  • Boundary markers: The SKILL.md instructions do not define explicit delimiters or 'ignore' instructions for the data being analyzed.\n
  • Capability inventory: The skill includes scripts for project analysis, dependency evaluation, and diagram generation, which involve reading and interpreting project structures.\n
  • Sanitization: The provided script templates do not currently implement filtering or sanitization of content read from the target directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — senior-architect