graphql-architect
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or remote code execution were detected. The skill content is entirely instructional and provides a framework for the AI to act as a GraphQL architect.
- [INDIRECT_PROMPT_INJECTION]: The skill constitutes a surface for indirect prompt injection because it is designed to process and analyze user-provided business requirements and data schemas. However, the overall risk is assessed as safe because the skill does not possess high-risk capabilities.
- Ingestion points: User-provided business requirements and technical GraphQL task descriptions in SKILL.md.
- Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are provided.
- Capability inventory: The skill possesses no scripting, file-writing, or network-access capabilities based on the provided file.
- Sanitization: No input sanitization or validation logic is defined.
- [EXTERNAL_DOWNLOADS]: The skill mentions various industry-standard tools and frameworks (e.g., Apollo, Prisma, GraphQL Yoga) within its knowledge base and capability descriptions, but it does not execute any automated downloads or installation commands.
Audit Metadata