ln-24-architecture-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from the repository being audited, such as architecture documents, manifests, and source code.
  • Ingestion points: The 'Discover the Actual Architecture' section instructs the agent to read repository instructions, architecture documents, manifests, entrypoints, and deployment definitions.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore malicious prompts embedded within the analyzed data.
  • Capability inventory: The skill is scoped to read-only actions, utilizing file listings, language servers, compiler metadata, and git history. It does not include tools for network exfiltration or writing to the filesystem.
  • Sanitization: The instructions lack explicit requirements for sanitizing or escaping the content retrieved from repository files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 04:09 PM
Security Audit — agent-trust-hub — ln-24-architecture-auditor