agent-native-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes architecture patterns, such as Shared Workspace and Files as Universal Interface, where agents process untrusted external data (e.g., web research, third-party files) while possessing powerful capabilities like file writing and shell access. This configuration creates a potential surface for indirect prompt injection attacks.
- Ingestion Points: Files within the shared workspace, including research documents, notes, and activity logs, as described in references/shared-workspace-architecture.md and references/files-universal-interface.md.
- Boundary Markers: The documentation recommends using structured context files (e.g., context.md) with explicit headers to manage state, though it does not define strict delimiters for all untrusted data.
- Capability Inventory: The patterns involve powerful primitives such as write_file, bash, call_api, and git_push as documented across multiple reference files.
- Sanitization: The documentation proactively recommends security controls, including human-in-the-loop 'Approval Gates' for high-stakes actions, path traversal checks for file operations, and using APIs as validators to ensure data integrity.
- [DYNAMIC_EXECUTION]: The references/self-modification.md and references/architecture-patterns.md files provide conceptual patterns and code templates for building agents that can modify their own source code, system prompts, and deployment configurations.
- Evidence: The references include examples of tools for writing to application source files (e.g., src/*.ts) and executing build/restart commands.
- Mitigation: The skill emphasizes the necessity of 'Approval Gates', automated commit/rollback mechanisms, and health checks to ensure that self-modification occurs safely and remains under user control.
Audit Metadata