graphql-architect
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture involves processing GraphQL schemas and query strings from external subgraphs and local files, which presents a surface for indirect prompt injection.
- Ingestion points: The skill utilizes
IntrospectAndComposeingateway/server.tsto poll subgraphs from remote URLs and usesfs.readFileSyncinusers-subgraph/resolvers.tsto load schema definitions. - Boundary markers: The skill does not explicitly define prompt boundaries or instructions to ignore embedded directives in the provided templates for external data.
- Capability inventory: The provided code samples demonstrate capabilities for filesystem access (
fs.readFileSync), database querying (db.users.findMany), and network interaction via the Apollo Gateway. - Sanitization: The skill proactively addresses these risks in
references/security.mdby providing templates for input validation usingzod, query depth limiting withgraphql-depth-limit, and query complexity analysis to prevent resource exhaustion.
Audit Metadata