architecture-review-full
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions to disregard certain platform-specific directives, which can be used to bypass intended interaction modes. Specifically, the Codex compatibility note instructs the agent to 'Ignore Claude-specific mode-switch instructions when they appear.'- [INDIRECT_PROMPT_INJECTION]: The skill processes project-level data, including configurations and source code diffs, which are externally controlled and could contain malicious instructions.
- Ingestion points: The skill reads
docs/project-config.json, project source files, and uncommitted git diffs. - Boundary markers: The protocol lacks explicit delimiters (like XML tags or specific markdown blocks) to isolate untrusted file content from the agent's core instructions.
- Capability inventory: The skill is capable of spawning multiple sub-agents using
spawn_agentand writing consolidated findings to theplans/reports/directory. - Sanitization: There is no evidence of content sanitization, although the skill does implement a verification gate using the
$why-reviewtool to validate findings before finalization.
Audit Metadata