arc42-review

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions are entirely focused on architectural quality review and follow best practices for documentation analysis.
  • [COMMAND_EXECUTION]: The skill facilitates the invocation of other specialized arc42 skills (e.g., /arc42-section-N) to address identified documentation gaps. This represents standard tool-chaining behavior within the platform and does not include arbitrary command execution.
  • [PROMPT_INJECTION]: The skill processes user-supplied documentation files, which constitutes a surface for indirect prompt injection.
  • Ingestion points: Local documentation files at paths provided by the user (Step 1).
  • Boundary markers: None explicitly implemented to delimit untrusted document content.
  • Capability inventory: Reading local files, writing/editing files, and calling other platform skills.
  • Sanitization: No specific sanitization or filtering of document content is described. Note: This risk is inherent to all document-processing skills and does not indicate malicious intent within this specific skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 11:22 AM
Security Audit — agent-trust-hub — arc42-review