ln-56-architecture-auditor
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns were detected. The skill explicitly defines a read-only execution contract, instructing the agent to perform analysis without modifying code or architecture documents.
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting untrusted data from repositories (source code, manifests, and documentation). While this constitutes an attack surface for indirect prompt injection, the skill includes a rigid checklist and instructions to maintain a read-only status and preserve existing authorizations, which mitigates the risk of the agent acting on instructions embedded in the analyzed code.
- [DATA_EXPOSURE_&_EXFILTRATION]: Although the skill mentions auditing secrets and configuration boundaries, this is framed as a diagnostic task for architectural integrity. There are no instructions to exfiltrate this data to external domains or hardcode credentials within the skill itself.
- [COMMAND_EXECUTION]: The skill leverages standard development tools (file listing, git, language servers) for repository analysis. It does not contain arbitrary shell execution patterns or unauthorized privilege escalation attempts.
Audit Metadata