senior-architect
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external project data via the target path arguments in its analysis scripts, creating an inherent attack surface for indirect prompt injection.\n
- Ingestion points: Source code, configuration files, and project metadata within the directory specified by the
target_pathparameter inscripts/project_architect.py,scripts/architecture_diagram_generator.py, andscripts/dependency_analyzer.py.\n - Boundary markers: The
SKILL.mdinstructions do not define explicit delimiters or 'ignore' instructions for the data being analyzed.\n - Capability inventory: The skill includes scripts for project analysis, dependency evaluation, and diagram generation, which involve reading and interpreting project structures.\n
- Sanitization: The provided script templates do not currently implement filtering or sanitization of content read from the target directory.
Audit Metadata