context-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines architectural principles and a procedural guide for repository audits. No malicious commands, obfuscation, or data exfiltration patterns were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves analyzing untrusted repository data to verify architectural claims, which represents a standard surface for indirect prompt injection.
  • Ingestion points: The agent reads the file tree, documentation files (README, AGENTS.md, CLAUDE.md), and source code during the Audit Phase.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are prescribed for the input data.
  • Capability inventory: The skill utilizes file system operations (reading/writing AGENTS.md, renaming folders) and command execution to verify that scripts and capabilities "still run" (Phase 3).
  • Sanitization: The methodology relies on the agent's internal reasoning and manual review steps rather than automated sanitization of ingested repository content.
  • Context: These capabilities are intrinsic to the primary purpose of a code auditing and restructuring tool and do not represent a malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 03:47 PM
Security Audit — agent-trust-hub — context-architecture