compass

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a multi-mode engineering coach that implements best practices for software design and architecture. It includes mechanisms for self-regulation, such as the 'Simplicity Guard,' which helps prevent overengineering and ensures recommendations are idiomatic to the user's chosen tech stack.- [DATA_EXPOSURE]: The skill performs legitimate file operations, specifically writing Architecture Decision Record (ADR) files to the docs/adr/ directory to document project decisions. This is an intended feature of the coach persona and does not involve unauthorized data access or exfiltration.- [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as source code, pull requests, and repository configuration files during code review and refactoring tasks.
  • Ingestion points: User-provided code snippets, PR diffs, and project documentation in the reviewer, refactor, and legacy workflows.
  • Boundary markers: None explicitly defined in the instructions to separate untrusted content from system instructions.
  • Capability inventory: Filesystem write access used for creating documentation in the docs/adr/ path.
  • Sanitization: None performed on the ingested code or metadata. While these factors create a surface for indirect prompt injection, the behavior is standard for development-oriented agents, and the impact is limited by the skill's specific focus on non-executable documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 02:41 PM
Security Audit — agent-trust-hub — compass