graphql-architect

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or remote code execution were detected. The skill content is entirely instructional and provides a framework for the AI to act as a GraphQL architect.
  • [INDIRECT_PROMPT_INJECTION]: The skill constitutes a surface for indirect prompt injection because it is designed to process and analyze user-provided business requirements and data schemas. However, the overall risk is assessed as safe because the skill does not possess high-risk capabilities.
  • Ingestion points: User-provided business requirements and technical GraphQL task descriptions in SKILL.md.
  • Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are provided.
  • Capability inventory: The skill possesses no scripting, file-writing, or network-access capabilities based on the provided file.
  • Sanitization: No input sanitization or validation logic is defined.
  • [EXTERNAL_DOWNLOADS]: The skill mentions various industry-standard tools and frameworks (e.g., Apollo, Prisma, GraphQL Yoga) within its knowledge base and capability descriptions, but it does not execute any automated downloads or installation commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 01:29 AM
Security Audit — agent-trust-hub — graphql-architect