arch-upkeep
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill functions as a conceptual framework and checklist for architecture upkeep. It does not include any automated execution logic or network-based operations.
- [NO_CODE]: The skill is composed entirely of instructional Markdown and YAML metadata. There are no associated scripts, executables, or configurations that perform active operations on the host system.
- [INDIRECT_PROMPT_INJECTION]: The skill outlines a process for analyzing external repository files (such as
package.json,manifest.json, and workspace configurations). While this represents a data ingestion surface, the skill itself does not implement the parsing logic or provide capabilities that could be exploited by malicious repository content. - [EXTERNAL_DOWNLOADS]: The skill suggests installing supplementary architecture skills from the platform's official catalog or marketplace if they are missing. This relies on the environment's native, trusted skill management system rather than external, untrusted URLs.
Audit Metadata