chief-architect

Fail

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill discloses a static production IP address (84.46.253.137) and detailed internal server paths (e.g., /opt/supabase/docker/, /etc/caddy/Caddyfile), providing a direct target for infrastructure attacks.
  • [COMMAND_EXECUTION]: Instructions explicitly direct the agent to perform privileged system operations, including SSH access as the root user and management of system services via systemctl and docker compose.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to read and process the 'entire codebase' and 'project documentation' without implementing sanitization or boundary markers.
  • [PROMPT_INJECTION]: Mandatory Evidence Chain for Category 8: 1. Ingestion points: Codebase files and docs/MASTER_PLAN.md (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Skill chaining to dev-debugging and tauri-debugger (shell command access). 4. Sanitization: Absent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 22, 2026, 01:14 AM
Security Audit — agent-trust-hub — chief-architect