feature-arch-gate

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a well-structured set of markdown instructions and rules. It does not contain any executable code, scripts, or commands that could compromise the host system.
  • [SAFE]: No data exfiltration or credential harvesting patterns were found. The skill does not perform network operations or access sensitive system files like SSH keys or environment secrets.
  • [SAFE]: While the skill processes untrusted user data (code diffs and documentation), which is a common surface for indirect prompt injection, it handles this by using a blind subagent focused solely on the review task. The ingestion points are located in references/reviewer-prompt.md ({{TARGET_CONTENT_OR_PATHS}} and {{BLUEPRINT_SECTION}}). No explicit boundary markers or sanitization logic are present, which is typical for this type of auditing tool and does not pose a significant security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 06:56 AM
Security Audit — agent-trust-hub — feature-arch-gate