chief-architect
Fail
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill discloses a static production IP address (84.46.253.137) and detailed internal server paths (e.g., /opt/supabase/docker/, /etc/caddy/Caddyfile), providing a direct target for infrastructure attacks.
- [COMMAND_EXECUTION]: Instructions explicitly direct the agent to perform privileged system operations, including SSH access as the root user and management of system services via systemctl and docker compose.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to read and process the 'entire codebase' and 'project documentation' without implementing sanitization or boundary markers.
- [PROMPT_INJECTION]: Mandatory Evidence Chain for Category 8: 1. Ingestion points: Codebase files and docs/MASTER_PLAN.md (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Skill chaining to dev-debugging and tauri-debugger (shell command access). 4. Sanitization: Absent.
Recommendations
- AI detected serious security threats
Audit Metadata