system-design
Fail
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: HIGHDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill integrates with the
likec4CLI tool, which supports executing arbitrary logic defined in workspace configuration files (likec4.config.ts,likec4.config.js) via thegeneratorsproperty. Because the agent is instructed to run this tool on untrusted repository content, a malicious project could achieve remote code execution (RCE) by providing a compromised configuration file that the agent then invokes during the validation or build phases. - Evidence:
likec4/references/configuration.mddetails thegeneratorsoption which executesasyncfunctions from the config file. - [REMOTE_CODE_EXECUTION]: The skill relies on executing the
likec4CLI and related packages (@likec4/leanix-bridge,@likec4/mcp) using package runners likenpx,bunx, andpnpm dlx. These dependencies are fetched from a third-party registry and are not associated with the provided list of trusted organizations or well-known services. - Evidence: Documented in
likec4/SKILL.mdandlikec4/references/cli.mdas standard commands for the agent to use. - [INDIRECT_PROMPT_INJECTION]: The
code-to-c4sub-skill is designed to ingest and process untrusted data from a user's repository, such as source code, build manifests, and deployment files, to reconstruct an architectural model. This creates a vulnerability where malicious content in the repository could manipulate the agent's summaries, evidence tables, or subsequent design recommendations. - Ingestion points:
code-to-c4/SKILL.mdspecifies reading repository instructions, manifests, executable entrypoints, and infrastructure definitions. - Boundary markers: No explicit boundary markers or 'ignore' instructions are used when interpolating this data into the architecture model.
- Capability inventory: The skill has the capability to perform repository-wide searches, read arbitrary files, and execute shell commands via the
likec4tool. - Sanitization: There is no evidence of sanitization or filtering applied to the source code content before it is processed by the agent.
Recommendations
- AI detected serious security threats
Audit Metadata