graphql-architect
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The instructions are strictly limited to technical guidance on GraphQL architecture and do not contain any patterns intended to bypass AI safety guardrails.
- [CREDENTIALS_UNSAFE]: The skill promotes secure practices by demonstrating the use of environment variables for authentication secrets and database connection strings.
- [EXTERNAL_DOWNLOADS]: Referenced Node.js packages are well-established, industry-standard libraries within the GraphQL ecosystem.
- [DATA_EXFILTRATION]: No patterns for unauthorized data access or transmission to untrusted external domains were detected.
- [OBFUSCATION]: The skill contains no hidden, encoded, or deceptive content.
- [DYNAMIC_EXECUTION]: Code examples follow best practices, such as using schema-first design and structured validation, avoiding unsafe execution patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided GraphQL schemas but lacks any active execution capabilities. It follows safety best practices by explicitly recommending boundary-enforcing techniques such as schema validation and query complexity limits.
- [METADATA_POISONING]: Although there is a minor discrepancy between the system-provided author name and the metadata link, the content itself is technically sound and presents no security risk to the user or the environment.
Audit Metadata