graphql-architect

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture involves processing GraphQL schemas and query strings from external subgraphs and local files, which presents a surface for indirect prompt injection.
  • Ingestion points: The skill utilizes IntrospectAndCompose in gateway/server.ts to poll subgraphs from remote URLs and uses fs.readFileSync in users-subgraph/resolvers.ts to load schema definitions.
  • Boundary markers: The skill does not explicitly define prompt boundaries or instructions to ignore embedded directives in the provided templates for external data.
  • Capability inventory: The provided code samples demonstrate capabilities for filesystem access (fs.readFileSync), database querying (db.users.findMany), and network interaction via the Apollo Gateway.
  • Sanitization: The skill proactively addresses these risks in references/security.md by providing templates for input validation using zod, query depth limiting with graphql-depth-limit, and query complexity analysis to prevent resource exhaustion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — graphql-architect