cloud-architect

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is purely instructional and advisory. It contains no script files, binaries, or command-line execution patterns. All analysis of the instructions reveals standard architectural guidance without any attempts at obfuscation, credential theft, or persistence.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided cloud requirements and generate complex Infrastructure as Code (IaC) and design patterns, which presents a standard theoretical attack surface for indirect prompt injection.
  • Ingestion points: Processes user-defined goals, constraints, and workload descriptions in SKILL.md.
  • Boundary markers: None present; the instructions do not explicitly delimit user-provided data from system instructions.
  • Capability inventory: The skill generates code snippets for Terraform, OpenTofu, CDK, Pulumi, and various cloud-native templates for user execution.
  • Sanitization: No explicit sanitization or validation logic is defined within the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 PM
Security Audit — agent-trust-hub — cloud-architect