jfrog-reference-architecture

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to assist users with JFrog Platform topology, sizing, and deployment planning using official documentation as a source of truth.
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation and reference materials from official vendor domains, including jfrog.com and github.com/jfrog. These are legitimate resources owned by the skill author.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external documentation files fetched at runtime.
  • Ingestion points: Content is retrieved from https://jfrog.com/reference-architecture/llms-full.txt and specific path indices as defined in SKILL.md and references/doc-access.md.
  • Boundary markers: The agent is instructed to use only the text from the fetch for factual claims and to cite sources, which helps delineate external data from internal instructions.
  • Capability inventory: The skill is restricted to informational workflows (sizing, topology, deployment advice) and does not utilize dangerous capabilities such as local file modification, arbitrary command execution, or network exfiltration of sensitive data.
  • Sanitization: While no explicit sanitization is mentioned, the data is sourced from a trusted vendor domain and used solely for generating responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 08:18 PM
Security Audit — agent-trust-hub — jfrog-reference-architecture