c4-to-eventcatalog

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes external, untrusted architectural models to generate documentation plans.
  • Ingestion points: The skill accepts user-supplied Structurizr DSL, C4-PlantUML, Mermaid C4, and Markdown architecture descriptions in Phase 1 (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the embedded content as non-instructional data.
  • Capability inventory: The skill has the capability to write files to the local disk (Phase 6) and triggers the execution of the catalog-documentation-creator skill to generate further documentation (Phase 7).
  • Sanitization: No sanitization, validation, or escaping of the user-provided architectural strings is performed before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 10:37 AM
Security Audit — agent-trust-hub — c4-to-eventcatalog