java-architect

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard local build tools like ./mvnw (Maven Wrapper) and ./gradlew (Gradle Wrapper) for running tests and verifying code coverage as part of the development workflow.
  • [CREDENTIALS_UNSAFE]: The configuration examples in references/spring-boot-setup.md and references/spring-security.md use common development placeholders and environment variable defaults (e.g., DATABASE_PASSWORD:demo, jwt.secret: your-256-bit-secret-key-here) which are standard practice for documentation and do not represent a credential leak.
  • [EXTERNAL_DOWNLOADS]: The skill uses standard Java ecosystem dependency management via Maven and Gradle. These tools fetch libraries from official repositories such as Maven Central when build commands are executed.
  • [PROMPT_INJECTION]: No evidence of instruction overrides, safety filter bypasses, or system prompt extraction attempts were found in the skill metadata or body.
  • [DATA_EXFILTRATION]: No suspicious network operations or sensitive file access patterns were identified. External API calls in the reactive programming examples target a documentation placeholder (api.example.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — java-architect