architecture-research
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and analyze potentially untrusted external content like source code, technical papers, and engineering posts (SKILL.md Steps 4 and 5).
- Ingestion points: The agent reads external repositories, manifests, and documentation to build an evidence ledger.
- Boundary markers: There are no specific instructions to use delimiters or ignore embedded instructions within the ingested material.
- Capability inventory: The agent is instructed to run experiments and verification commands (SKILL.md Step 6) and browse the web.
- Sanitization: The skill focuses on verification but does not specify technical sanitization for the inputs being processed.
- [COMMAND_EXECUTION]: The skill defines a process for running representative workloads and verification commands against candidate systems to measure quality scenarios (SKILL.md Step 6). This is a functional requirement of the research process.
Audit Metadata