skills/mryll/skills/c4-model/Gen Agent Trust Hub

c4-model

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests data from external codebase files (e.g., cmd/*, go.mod, deployment manifests) to generate architecture diagrams, as outlined in references/codebase-analysis.md. This ingestion creates an indirect prompt injection surface where malicious content in a repository could attempt to influence the agent's output. However, the risk is considered low because the skill is limited to generating documentation and does not possess dangerous execution or network capabilities.
  • Ingestion points: Files within the analyzed repository such as source code and build configurations.
  • Boundary markers: Not explicitly defined in the instructions for codebase input processing.
  • Capability inventory: Limited to generating Markdown text and diagram-as-code (PlantUML/Mermaid).
  • Sanitization: None specified for the processed codebase content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 04:41 AM
Security Audit — agent-trust-hub — c4-model