ln-25-architecture-diagram-builder
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows least-privilege principles by restricting the agent's write access to specific architecture documentation paths (
docs/architecture/diagrams/) and explicitly requiring read-only behavior for repository analysis. It also includes instructions to block actions if evidence boundaries are unsafe.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted data from repository source code, configuration files, and infrastructure-as-code to build architecture models. This represents an inherent surface for indirect prompt injection, though it is the primary intended function of the skill.\n - Ingestion points: Repository files, infrastructure-as-code (IaC), and system contracts analyzed during diagram construction.\n
- Boundary markers: The checklist requires defining an 'evidence boundary' and labeling unverified or user-supplied elements separately to prevent model poisoning.\n
- Capability inventory: The skill reads repository files and writes Mermaid or ASCII diagrams to specific markdown files.\n
- Sanitization: Includes requirements for syntax verification and manual inspection of the generated diagram source.
Audit Metadata