agent-repo-architect

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to execute the ruv-swarm package during several lifecycle hooks (pre_task, post_edit, post_task, and notification). It also includes ruv-swarm as a dependency in the generated package.json templates for new projects.
  • [COMMAND_EXECUTION]: The skill executes shell commands via the Bash tool to perform GitHub repository searches using the gh CLI. It also runs automated hooks via the shell to coordinate architecture analysis and validation tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface for indirect prompt injection because it ingests data from external sources and has significant system capabilities.
  • Ingestion points: Untrusted data enters the agent context through the WebFetch tool and the results of gh search commands (SKILL.md).
  • Boundary markers: No explicit delimiters or specific instructions to ignore embedded commands are defined for the processed external content.
  • Capability inventory: The skill is equipped with capabilities for file writing (Write), pushing content to remote repositories (mcp__github__push_files), and orchestrating multi-agent tasks (mcp__claude-flow__*).
  • Sanitization: There is no evidence of content sanitization, escaping, or strict schema validation for the data retrieved from external sources before it is analyzed by the agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — agent-repo-architect