architecture-synthesis
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from project overlays and a persistent knowledge graph (synthesis-state.json). Ingestion points include the synthesis-state.json file and relative project paths. The skill defines clear boundary markers (<<<UNTRUSTED_HINT>>>, <<<SYNTHESIS_STATE_CACHE>>>) and instructs the agent to treat this content as non-authoritative evidence. Capabilities include suggesting code modifications, and sanitization relies on schema validation and explicit priority instructions.
- [INDIRECT_PROMPT_INJECTION]: The README.md file contains a 'Claim-by-claim rebuttal' against automated security scanners. This is a self-referential pattern (Category 8e) where the skill content explicitly attempts to influence the security assessment of the analyzer.
- [PROMPT_INJECTION]: The skill uses terminology such as 'self-amplification' and 'self-improve'. These directives are constrained by guardrails that limit their application to project-level code and prohibit modification of the skill's own package, but they represent a surface for potential instruction override.
Audit Metadata