create-architecture
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The script
examples/learn_chart_examples.pyutilizessubprocess.runto invoke an internal CLI (graph_memory.agent_cli). This implementation follows security best practices by passing arguments as a list rather than a single string withshell=True, effectively preventing shell injection vulnerabilities. - [SAFE]: The primary functionality in
create_architecture.pyinvolves communicating with a local server (localhost:3001) via HTTP PUT requests. This is consistent with the skill's purpose as a local visualization tool for developers. - [SAFE]: The skill implements a security-conscious 'Mutation Authorization Gate' that requires a human-authored JSON file (
--execution-gate) to permit architecture modifications, ensuring human-in-the-loop control for sensitive operations. - [SAFE]: Pipeline definitions are parsed using
yaml.safe_load(), which protects against YAML-based code execution attacks.
Audit Metadata