java-architect
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation link 'https://jeffallan.github.io/claude-skills/skills/language/java-architect/' referenced in SKILL.md is blacklisted as malicious by automated reputation scanners (URLite).
- [COMMAND_EXECUTION]: The skill instructs the agent to run './mvnw' and './gradlew' commands as part of the development workflow. This allows for arbitrary code execution if the target project contains malicious build wrappers or configurations.
- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface as it processes external Java source code and configuration data. 1. Ingestion points: Java files, pom.xml, and build.gradle files. 2. Boundary markers: None present. 3. Capability inventory: Command execution and filesystem access. 4. Sanitization: None implemented.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata