graphql-architect

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The instructions are strictly limited to technical guidance on GraphQL architecture and do not contain any patterns intended to bypass AI safety guardrails.
  • [CREDENTIALS_UNSAFE]: The skill promotes secure practices by demonstrating the use of environment variables for authentication secrets and database connection strings.
  • [EXTERNAL_DOWNLOADS]: Referenced Node.js packages are well-established, industry-standard libraries within the GraphQL ecosystem.
  • [DATA_EXFILTRATION]: No patterns for unauthorized data access or transmission to untrusted external domains were detected.
  • [OBFUSCATION]: The skill contains no hidden, encoded, or deceptive content.
  • [DYNAMIC_EXECUTION]: Code examples follow best practices, such as using schema-first design and structured validation, avoiding unsafe execution patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided GraphQL schemas but lacks any active execution capabilities. It follows safety best practices by explicitly recommending boundary-enforcing techniques such as schema validation and query complexity limits.
  • [METADATA_POISONING]: Although there is a minor discrepancy between the system-provided author name and the metadata link, the content itself is technically sound and presents no security risk to the user or the environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:57 PM
Security Audit — agent-trust-hub — graphql-architect