architecture-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a passive analyzer for Flutter codebases. It performs read-only operations on the project structure and source files using standard Unix utilities such as
find,grep, andwc. No suspicious network activity, file modification, or credential access was detected. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code and configuration files (
pubspec.yaml,.dartfiles) to generate its audit report. This constitutes a potential indirect prompt injection surface where malicious content within the analyzed files could attempt to influence the agent's architectural conclusions. However, the skill instructions provide a structured, evidence-based workflow that requires the agent to map findings to concrete files, mitigating the risk of accidental obedience to embedded instructions. - [COMMAND_EXECUTION]: The skill employs shell commands to automate the discovery of the project structure and identify technical debt indicators, such as file line counts. These commands (e.g.,
find lib/ -type f -name '*.dart',grep -r "import.*features/",wc -l) are targeted at the locallib/directory and are used strictly for diagnostic purposes within the defined scope of the audit.
Audit Metadata