powercat-pp-architecture-advisor

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Regulated Data Guidance: The skill provides architectural advice for scenarios involving sensitive data, including HIPAA, PCI-DSS, and GDPR. It correctly identifies compliance requirements, such as BAA agreements for health data and tokenization for payment systems, rather than attempting to store sensitive information directly.
  • External Document Ingestion: The skill is designed to process user-provided documents to extract business requirements. While this is a primary function, it represents a surface where external content could influence the agent's reasoning. The skill mitigates this by using structured discovery and an assumption-review process to confirm findings with the user.
  • Secure Handoff Artifacts: The 'Pause and Email' feature generates .eml and .html files for discovery handoffs. The instructions explicitly mandate the validation of email addresses and the rejection of line breaks or other characters that could be used for email header injection attacks.
  • Controlled Workspace Interaction: The skill maintains a learning log within the repository to improve its pattern recognition. This is a functional state-management feature that uses the platform's file-editing tools to persist non-sensitive architectural patterns across sessions.
  • Fitness Guardrails: A notable security feature is the inclusion of a fitness check that proactively discourages the use of the platform for inappropriate mission-critical tasks, such as emergency dispatch or high-frequency trading, citing safety and latency constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:58 AM
Security Audit — agent-trust-hub — powercat-pp-architecture-advisor