jfrog-reference-architecture
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed to assist users with JFrog Platform topology, sizing, and deployment planning using official documentation as a source of truth.
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation and reference materials from official vendor domains, including
jfrog.comandgithub.com/jfrog. These are legitimate resources owned by the skill author. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external documentation files fetched at runtime.
- Ingestion points: Content is retrieved from
https://jfrog.com/reference-architecture/llms-full.txtand specific path indices as defined inSKILL.mdandreferences/doc-access.md. - Boundary markers: The agent is instructed to use only the text from the fetch for factual claims and to cite sources, which helps delineate external data from internal instructions.
- Capability inventory: The skill is restricted to informational workflows (sizing, topology, deployment advice) and does not utilize dangerous capabilities such as local file modification, arbitrary command execution, or network exfiltration of sensitive data.
- Sanitization: While no explicit sanitization is mentioned, the data is sourced from a trusted vendor domain and used solely for generating responses.
Audit Metadata