create-architecture

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script examples/learn_chart_examples.py utilizes subprocess.run to invoke an internal CLI (graph_memory.agent_cli). This implementation follows security best practices by passing arguments as a list rather than a single string with shell=True, effectively preventing shell injection vulnerabilities.
  • [SAFE]: The primary functionality in create_architecture.py involves communicating with a local server (localhost:3001) via HTTP PUT requests. This is consistent with the skill's purpose as a local visualization tool for developers.
  • [SAFE]: The skill implements a security-conscious 'Mutation Authorization Gate' that requires a human-authored JSON file (--execution-gate) to permit architecture modifications, ensuring human-in-the-loop control for sensitive operations.
  • [SAFE]: Pipeline definitions are parsed using yaml.safe_load(), which protects against YAML-based code execution attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — create-architecture