cld-archetypes
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or data exfiltration vectors were identified across the 6 analyzed files. The skill focuses on system thinking diagnostics using Mermaid diagrams and text-based symptoms.
- [COMMAND_EXECUTION]: No shell commands, subprocess spawning, or dynamic code execution patterns were found. The skill does not utilize the dynamic context injection syntax (
!command). - [DATA_EXFILTRATION]: There are no network-capable commands (curl, wget) or attempts to access sensitive local file paths (e.g., .ssh, .aws, .env).
- [PROMPT_INJECTION]: The instructions follow standard agent role-definition and task-specific logic without attempting to override safety filters, extract system prompts, or bypass ethical guidelines.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface via user-provided symptoms and Mermaid diagrams.
- Ingestion points: User input text and Mermaid CLD code (SKILL.md).
- Boundary markers: The skill uses structured logic steps and reference cases to guide analysis, though it does not explicitly define unique delimiters for user input.
- Capability inventory: No execution capabilities (eval, exec, subprocess) or network/file write tools are used.
- Sanitization: None specified, which is standard for instructions of this nature.
Audit Metadata