cld-archetypes

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or data exfiltration vectors were identified across the 6 analyzed files. The skill focuses on system thinking diagnostics using Mermaid diagrams and text-based symptoms.
  • [COMMAND_EXECUTION]: No shell commands, subprocess spawning, or dynamic code execution patterns were found. The skill does not utilize the dynamic context injection syntax (!command).
  • [DATA_EXFILTRATION]: There are no network-capable commands (curl, wget) or attempts to access sensitive local file paths (e.g., .ssh, .aws, .env).
  • [PROMPT_INJECTION]: The instructions follow standard agent role-definition and task-specific logic without attempting to override safety filters, extract system prompts, or bypass ethical guidelines.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface via user-provided symptoms and Mermaid diagrams.
  • Ingestion points: User input text and Mermaid CLD code (SKILL.md).
  • Boundary markers: The skill uses structured logic steps and reference cases to guide analysis, though it does not explicitly define unique delimiters for user input.
  • Capability inventory: No execution capabilities (eval, exec, subprocess) or network/file write tools are used.
  • Sanitization: None specified, which is standard for instructions of this nature.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:06 PM
Security Audit — agent-trust-hub — cld-archetypes