ln-26-architecture-migration-planner

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed strictly for planning and documentation. The instructions explicitly forbid the execution of migrations, editing product code, or approving delivery, which mitigates risks associated with unintended system changes.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it is instructed to ingest data from untrusted sources, including repository artifacts, Git state, deployment configurations, and external vendor migration guides (SKILL.md, Checklist Section 1 and Tool Routing). Ingestion points: Repository instructions, Git state, architecture artifacts, and external vendor documentation. Boundary markers: The skill instructions do not specify explicit delimiters or isolation for external content. Capability inventory: The skill is limited to reading repository information and writing to a specific markdown artifact (docs/architecture/migration-plan.md); it lacks capabilities for arbitrary command execution, network exfiltration, or privileged file access. Sanitization: No explicit sanitization or filtering of external content is described. The risk is minimized by the skill's restricted output scope and lack of execution capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 03:19 PM
Security Audit — agent-trust-hub — ln-26-architecture-migration-planner