appfolio-reference-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an informational reference for building property management integrations. It provides architectural guidance and TypeScript snippets for service layers, caching, and event processing.
  • [SAFE]: Security best practices are explicitly integrated into the instructions, including recommendations for environment separation, data classification (encrypting tenant contact and payment data), and implementing idempotency records to prevent duplicate financial mutations.
  • [INDIRECT_PROMPT_INJECTION]: The architecture describes a system that ingests external webhook data via the PropertyEventPipeline class.
  • Ingestion points: The onWebhook method in SKILL.md receives AppFolioEvent data from external sources.
  • Boundary markers: Instructions mandate the use of provider-verified contracts and the validation of "signature, persistence, and replay boundaries" before processing events.
  • Capability inventory: The skill configuration allows for Read, Write, Edit, Bash, and Grep tools.
  • Sanitization: The skill recommends using "synthetic fixtures" for testing and requiring explicit authorization for mutations.
  • [SAFE]: External links point to official AppFolio domains (appfolio.com), which are legitimate and directly related to the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:40 AM
Security Audit — agent-trust-hub — appfolio-reference-architecture