architecture-diagram-creator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by analyzing project files (README and source code) to generate diagrams. This surface could be exploited if an attacker includes malicious instructions within project documentation to influence the agent's behavior.
- Ingestion points: The skill instructions specify analyzing the project README and code structure in SKILL.md.
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the analyzed project files are defined.
- Capability inventory: The skill is authorized to perform file-writing operations to save the generated architecture HTML report.
- Sanitization: No explicit sanitization or validation of extracted project metadata is defined before it is interpolated into the HTML template.
Audit Metadata