feature-arch
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is primarily composed of architectural rules, templates, and process guides in Markdown format. It does not include scripts, executables, or hidden commands. All identified external links point to reputable technology documentation and established community resources.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze local project files such as
package.json,README.md, and the source code tree to identify business features. While reading project files is an ingestion point for indirect prompt injection, the risk is assessed as safe as the agent's actions are restricted to interacting with the user for confirmation and writing a markdown blueprint to the project's own documentation directory. - Ingestion points: Project configuration and source files (e.g.,
package.json,src/,README.md,CLAUDE.md) are read during the blueprint generation process described inreferences/_blueprint-process.md. - Boundary markers: The skill does not define specific boundaries or ignore-tags for the data it reads, relying on the agent's inherent processing capabilities.
- Capability inventory: The skill is limited to file system read access for context gathering and writing a single documentation file (
docs/architecture/FEATURE-ARCH-TARGET.md). It does not utilize network access or shell command execution. - Sanitization: There are no explicit sanitization routines defined in the skill, as the agent is expected to interpret technical context for architectural categorization.
Audit Metadata