security-architect

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external files and codebases, which introduces a potential surface for indirect prompt injection from the target data. However, the skill explicitly includes mitigation instructions and best practices for agents to handle these risks.
  • Ingestion points: The target parameter in schemas/input.schema.json defines the files or directories to be read by the agent.
  • Boundary markers: The skill documentation in knowledge/owasp-agentic-ai-top-10.md (ASI08) instructs the agent to use clear delineation markers and "ignore instructions" headers for untrusted external content.
  • Capability inventory: The skill uses Read, Write, Edit, Bash, Glob, and Grep tools to conduct audits and generate reports.
  • Sanitization: The skill provides specific code patterns and instructional guardrails for validating and sanitizing retrieved content before it enters the context window.
  • [EXTERNAL_DOWNLOADS]: The skill manifest and documentation reference external tools and repositories for legitimate security research purposes.
  • The manifest.json file identifies semgrep and trufflehog as optional CLI dependencies, which are industry-standard security auditing tools.
  • It also includes research references to official OWASP GitHub repositories (CheatSheetSeries and ASVS) for security verification standards.
  • All referenced sources are well-known security organizations or established open-source projects.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:59 AM
Security Audit — agent-trust-hub — security-architect