replit-reference-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a set of design patterns and instructions for creating secure Replit applications. It emphasizes security best practices such as separating secrets from configuration, implementing server-side authentication, and minimizing public operational endpoints.
- [INDIRECT_PROMPT_INJECTION]: The skill instructions involve using
ReadandGrepto analyze existing project architecture. This represents a potential surface for indirect prompt injection if the project files contain malicious instructions designed to influence the agent's architectural advice. However, the skill has no destructive capabilities, network access, or command execution tools, limiting the potential impact. - Ingestion points:
SKILL.md(Step 1 instructions to read existing architecture). - Boundary markers: Absent.
- Capability inventory:
ReadandGreptools only. - Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]: The skill contains several links to official Replit documentation (
docs.replit.com). These are references to a well-known service and are used to provide the user with authoritative resources for the platform.
Audit Metadata