ln-72-current-architecture-documenter

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently processes untrusted data from the repository (source code, manifests, and configuration files) to generate architecture documentation, creating a vulnerability surface.
  • Ingestion points: The skill instructions in SKILL.md require the agent to read repository manifests, CI configurations, source code symbols, Infrastructure as Code (IaC) files, and existing documentation.
  • Boundary markers: There are no explicit instructions or delimiters defined to ensure the agent ignores natural language instructions that might be embedded within the source code or comments it analyzes.
  • Capability inventory: The skill utilizes file system reads, Git status/branch commands, and has the capability to write or patch documentation files (defaulting to docs/architecture/current-state.md).
  • Sanitization: No specific sanitization, validation, or filtering of the ingested external content is mentioned before the information is processed and written to the output document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 04:27 AM
Security Audit — agent-trust-hub — ln-72-current-architecture-documenter