architecture-audit

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a logical workflow for architectural reviews, prioritizing code-level evidence over documentation. It uses structured templates for output which promotes clarity.\n- [PROMPT_INJECTION]: The skill defines a reporting taxonomy using terms like 'CRITICAL' and 'Verdict'. These are intended for the audit's findings and do not attempt to override the underlying agent safety guidelines.\n- [PROMPT_INJECTION]: While the skill ingests untrusted source code (a surface for indirect prompt injection), the risk is inherent to the audit function and is mitigated by the skill's requirement for specific file references and structured report sections.\n
  • Ingestion points: Reads codebase entry points, build files, and dependency manifests in Step 1.\n
  • Boundary markers: The workflow uses structured markdown templates for findings but lacks explicit instructions for the agent to ignore or delimit instructions found within the audited code.\n
  • Capability inventory: The skill uses standard file-reading capabilities and coordination with other agent skills like 'dispatching-parallel-agents'.\n
  • Sanitization: No specific content sanitization or escaping is mentioned for the final consolidated report.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 11:26 AM
Security Audit — agent-trust-hub — architecture-audit