create-architecture

Warn

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax to execute a shell command (source "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/yaml-helper.sh" 2>/dev/null && resolve_config --keys review_mode,automation,workflow,docs.density) when the skill is loaded. This allows for the execution of local scripts to dynamically populate skill parameters.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to use the Grep and Bash tools. Specifically, it uses Grep with context flags (-A 40) to scan and extract sections from design documents (design/gdd/*.md).
  • [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: The skill reads and processes potentially untrusted content from multiple project files, including all GDDs in design/gdd/*.md and engine reference documentation. 2. Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following directives that might be embedded within the design documents it processes. 3. Capability inventory: The skill has access to powerful tools including Bash, Write, Read, Glob, Grep, and Agent (orchestration). 4. Sanitization: Content extracted from design files is used directly in architecture generation and decision-making without a defined sanitization or validation process.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 24, 2026, 09:12 AM
Security Audit — agent-trust-hub — create-architecture