code-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze project source code and folder structures using tools like Grep, Glob, and Bash. This creates a surface for indirect prompt injection where an attacker could place malicious instructions within comments, file names, or metadata of a codebase being analyzed by an agent using this skill.
  • Ingestion points: Source code files and directory structures accessed via Read, Grep, and Glob tools as defined in SKILL.md.
  • Boundary markers: None present in the instructions to delimit analyzed code from agent instructions.
  • Capability inventory: The skill allows usage of Bash, Write, and Edit tools (SKILL.md frontmatter).
  • Sanitization: No explicit instructions for sanitizing or escaping the content of analyzed source files are provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 05:08 PM
Security Audit — agent-trust-hub — code-architecture