lov-solution-architect

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a professional consultant for solution architecture and technology selection. It uses a structured workflow to analyze user requirements and provide research-backed recommendations.\n- [DATA_EXPOSURE]: The skill interacts with platform-provided runtime context (skill-runtime/v1) to access brand profiles and user preferences. The instructions explicitly direct the agent to avoid including secrets, private file paths, or raw configurations in diagnostic logs, which is a positive security practice.\n- [INDIRECT_PROMPT_INJECTION]: The skill utilizes web browsing capabilities to research current technology, pricing, and project health. This is a standard operational feature that involves ingesting data from untrusted external sources (e.g., public GitHub repositories). The skill mitigates potential injection risks by requiring the agent to cite official sources and clearly separate confirmed facts from assumptions.\n- [COMMAND_EXECUTION]: While the README provides an installation command for a CLI tool (npx skills add), the skill itself does not contain any instructions to execute arbitrary shell commands or spawn subprocesses during runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 12:55 AM
Security Audit — agent-trust-hub — lov-solution-architect