java-architect
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides purely instructional content for architectural analysis and Java development. It does not include any executable scripts, network commands, or persistence mechanisms.
- [PROMPT_INJECTION]: No attempts to override system prompts, bypass safety guidelines, or extract system instructions were found. The 'Communication Protocol' and 'Development Workflow' sections use structured JSON for benign progress tracking and context gathering.
- [DATA_EXFILTRATION]: There are no patterns suggesting the collection or transmission of sensitive user data. The skill focuses on standard project metadata such as Spring Boot versions and dependency management.
- [REMOTE_CODE_EXECUTION]: The skill mentions build tools like Maven and Gradle, but does not provide commands to download or execute untrusted remote scripts.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external Java project structures and configuration files. While this creates a surface for indirect prompt injection from codebase content, the skill does not utilize tools or commands that could be exploited to perform unauthorized actions on the host system.
Audit Metadata