security-architect
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external files and codebases, which introduces a potential surface for indirect prompt injection from the target data. However, the skill explicitly includes mitigation instructions and best practices for agents to handle these risks.
- Ingestion points: The
targetparameter inschemas/input.schema.jsondefines the files or directories to be read by the agent. - Boundary markers: The skill documentation in
knowledge/owasp-agentic-ai-top-10.md(ASI08) instructs the agent to use clear delineation markers and "ignore instructions" headers for untrusted external content. - Capability inventory: The skill uses
Read,Write,Edit,Bash,Glob, andGreptools to conduct audits and generate reports. - Sanitization: The skill provides specific code patterns and instructional guardrails for validating and sanitizing retrieved content before it enters the context window.
- [EXTERNAL_DOWNLOADS]: The skill manifest and documentation reference external tools and repositories for legitimate security research purposes.
- The
manifest.jsonfile identifiessemgrepandtrufflehogas optional CLI dependencies, which are industry-standard security auditing tools. - It also includes research references to official OWASP GitHub repositories (CheatSheetSeries and ASVS) for security verification standards.
- All referenced sources are well-known security organizations or established open-source projects.
Audit Metadata