agent-repo-architect
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto execute theruv-swarmpackage during several lifecycle hooks (pre_task,post_edit,post_task, andnotification). It also includesruv-swarmas a dependency in the generatedpackage.jsontemplates for new projects. - [COMMAND_EXECUTION]: The skill executes shell commands via the
Bashtool to perform GitHub repository searches using theghCLI. It also runs automated hooks via the shell to coordinate architecture analysis and validation tasks. - [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface for indirect prompt injection because it ingests data from external sources and has significant system capabilities.
- Ingestion points: Untrusted data enters the agent context through the
WebFetchtool and the results ofgh searchcommands (SKILL.md). - Boundary markers: No explicit delimiters or specific instructions to ignore embedded commands are defined for the processed external content.
- Capability inventory: The skill is equipped with capabilities for file writing (
Write), pushing content to remote repositories (mcp__github__push_files), and orchestrating multi-agent tasks (mcp__claude-flow__*). - Sanitization: There is no evidence of content sanitization, escaping, or strict schema validation for the data retrieved from external sources before it is analyzed by the agents.
Audit Metadata