replit-reference-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a set of design patterns and instructions for creating secure Replit applications. It emphasizes security best practices such as separating secrets from configuration, implementing server-side authentication, and minimizing public operational endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions involve using Read and Grep to analyze existing project architecture. This represents a potential surface for indirect prompt injection if the project files contain malicious instructions designed to influence the agent's architectural advice. However, the skill has no destructive capabilities, network access, or command execution tools, limiting the potential impact.
  • Ingestion points: SKILL.md (Step 1 instructions to read existing architecture).
  • Boundary markers: Absent.
  • Capability inventory: Read and Grep tools only.
  • Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: The skill contains several links to official Replit documentation (docs.replit.com). These are references to a well-known service and are used to provide the user with authoritative resources for the platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:47 AM
Security Audit — agent-trust-hub — replit-reference-architecture