c4-architecture

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is well-structured and focuses on providing instructional context for the agent to generate architecture diagrams. It does not include any executable code, external dependencies, or network-enabled tools. All instructions are dedicated to documentation best practices and Mermaid syntax.
  • [NO_CODE]: The skill consists entirely of Markdown documentation and reference files, with no associated scripts or executable files, which significantly reduces the technical attack surface.
  • [PROMPT_INJECTION]: The skill possesses a potential surface for indirect prompt injection because it is designed to analyze a user's codebase. Maliciously crafted comments or documentation within the codebase could theoretically attempt to influence the agent's output. However, since the skill's capabilities are limited to generating markdown documentation in a specific directory, the risk is minimal. Mandatory Evidence Chain: 1. Ingestion points: Step 2 of the workflow in 'SKILL.md' (Analyze codebase). 2. Boundary markers: Absent. 3. Capability inventory: Writing diagrams to markdown files in 'docs/architecture/'. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — c4-architecture