microservices-architect

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSDATA_EXFILTRATIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation URL 'https://jeffallan.github.io/claude-skills/skills/api-architecture/microservices-architect/' listed in SKILL.md is flagged as malicious by automated scanners (URLite). This poses a severe risk if the agent or a user attempts to fetch or visit the external documentation site.
  • [METADATA_POISONING]: The SKILL.md file itself has been flagged as malicious by file reputation scanners (FileRepMalware). This indicates that the skill's primary instruction set is associated with known malicious signatures or behaviors.
  • [DATA_EXFILTRATION]: The inclusion of a flagged malicious URL in a trusted reference section creates a vector for data exfiltration. If the agent were to transmit context to this URL for documentation lookup, sensitive architecture details could be intercepted.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external architectural requirements and domain descriptions, creating an attack surface for indirect prompt injection where malicious instructions could be embedded in the system descriptions provided by a user.
  • Ingestion points: The skill accepts user-defined monolith descriptions, service boundaries, and system requirements via SKILL.md workflow steps.
  • Boundary markers: The instructions lack explicit delimiters or 'ignore' directives to separate user-provided data from architectural logic.
  • Capability inventory: The skill is limited to generating text and diagrams; it does not contain direct shell or network execution tools in its current state.
  • Sanitization: No input validation or sanitization is defined for the user-supplied domain names or requirements.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 11:36 AM
Security Audit — agent-trust-hub — microservices-architect