domain-modeling
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is strictly focused on domain modeling and architectural documentation. It lacks any functionality for network communication, external downloads, or execution of system commands.
- [SAFE]: No obfuscation, privilege escalation, or persistence mechanisms were found within the skill's instructions or configuration files.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface by ingesting external project documentation.
- Ingestion points: Files including
CONTEXT.md,CONTEXT-MAP.md, and architectural decision records indocs/adr/are read into the agent's context. - Boundary markers: The skill does not specify explicit delimiters or instruction-bypass warnings when reading these files.
- Capability inventory: The skill's actions are restricted to reading files and creating or updating markdown documentation. It lacks the ability to execute code or perform network operations.
- Sanitization: Content from project files is processed as natural language without programmatic sanitization or validation beyond formatting rules.
Audit Metadata