architecture-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a passive analyzer for Flutter codebases. It performs read-only operations on the project structure and source files using standard Unix utilities such as find, grep, and wc. No suspicious network activity, file modification, or credential access was detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code and configuration files (pubspec.yaml, .dart files) to generate its audit report. This constitutes a potential indirect prompt injection surface where malicious content within the analyzed files could attempt to influence the agent's architectural conclusions. However, the skill instructions provide a structured, evidence-based workflow that requires the agent to map findings to concrete files, mitigating the risk of accidental obedience to embedded instructions.
  • [COMMAND_EXECUTION]: The skill employs shell commands to automate the discovery of the project structure and identify technical debt indicators, such as file line counts. These commands (e.g., find lib/ -type f -name '*.dart', grep -r "import.*features/", wc -l) are targeted at the local lib/ directory and are used strictly for diagnostic purposes within the defined scope of the audit.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:23 PM
Security Audit — agent-trust-hub — architecture-auditor