ln-56-architecture-auditor

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns were detected. The skill explicitly defines a read-only execution contract, instructing the agent to perform analysis without modifying code or architecture documents.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting untrusted data from repositories (source code, manifests, and documentation). While this constitutes an attack surface for indirect prompt injection, the skill includes a rigid checklist and instructions to maintain a read-only status and preserve existing authorizations, which mitigates the risk of the agent acting on instructions embedded in the analyzed code.
  • [DATA_EXPOSURE_&_EXFILTRATION]: Although the skill mentions auditing secrets and configuration boundaries, this is framed as a diagnostic task for architectural integrity. There are no instructions to exfiltrate this data to external domains or hardcode credentials within the skill itself.
  • [COMMAND_EXECUTION]: The skill leverages standard development tools (file listing, git, language servers) for repository analysis. It does not contain arbitrary shell execution patterns or unauthorized privilege escalation attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 07:49 AM
Security Audit — agent-trust-hub — ln-56-architecture-auditor