java-architect
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill core workflow involves executing the Maven wrapper (
./mvnw verify) and Gradle wrapper (./gradlew check) to validate project structure, confirm query correctness, and verify security configurations. These actions are standard for developer-centric tools and are performed within the project context.\n- [PROMPT_INJECTION]: The skill processes untrusted workspace data by reading Hibernate SQL logs and JaCoCo coverage reports to identify performance bottlenecks and missing test cases. This creates an indirect prompt injection surface where external file content influences agent decisions.\n - Ingestion points: Project log files and HTML coverage reports (
target/site/jacoco/index.html).\n - Boundary markers: Absent.\n
- Capability inventory: Shell command execution via project build wrappers (
./mvnw,./gradlew).\n - Sanitization: No filtering or validation of ingested log/report content is described.
Audit Metadata