ln-25-architecture-diagram-builder

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows least-privilege principles by restricting the agent's write access to specific architecture documentation paths (docs/architecture/diagrams/) and explicitly requiring read-only behavior for repository analysis. It also includes instructions to block actions if evidence boundaries are unsafe.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted data from repository source code, configuration files, and infrastructure-as-code to build architecture models. This represents an inherent surface for indirect prompt injection, though it is the primary intended function of the skill.\n
  • Ingestion points: Repository files, infrastructure-as-code (IaC), and system contracts analyzed during diagram construction.\n
  • Boundary markers: The checklist requires defining an 'evidence boundary' and labeling unverified or user-supplied elements separately to prevent model poisoning.\n
  • Capability inventory: The skill reads repository files and writes Mermaid or ASCII diagrams to specific markdown files.\n
  • Sanitization: Includes requirements for syntax verification and manual inspection of the generated diagram source.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 03:19 PM
Security Audit — agent-trust-hub — ln-25-architecture-diagram-builder