create-architecture
Warn
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!syntax to execute a shell command (source "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/yaml-helper.sh" 2>/dev/null && resolve_config --keys review_mode,automation,workflow,docs.density) when the skill is loaded. This allows for the execution of local scripts to dynamically populate skill parameters. - [COMMAND_EXECUTION]: The skill instructions direct the agent to use the
GrepandBashtools. Specifically, it usesGrepwith context flags (-A 40) to scan and extract sections from design documents (design/gdd/*.md). - [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: The skill reads and processes potentially untrusted content from multiple project files, including all GDDs in
design/gdd/*.mdand engine reference documentation. 2. Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following directives that might be embedded within the design documents it processes. 3. Capability inventory: The skill has access to powerful tools includingBash,Write,Read,Glob,Grep, andAgent(orchestration). 4. Sanitization: Content extracted from design files is used directly in architecture generation and decision-making without a defined sanitization or validation process.
Audit Metadata