cloud-architect

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous shell command examples for cloud provider CLIs (AWS, Azure, GCP) intended for infrastructure validation and cost monitoring. These include tools for checking VPC peering status, target group health, and cost usage reports.- [INDIRECT_PROMPT_INJECTION]: The skill defines a discovery workflow that ingests user-supplied requirements to design architectures.
  • Ingestion points: Requirement discovery and compliance constraint inputs defined in the Core Workflow section of SKILL.md.
  • Boundary markers: The workflow structure provides logical separation of tasks, but no explicit markers or sanitization for user-provided data are defined.
  • Capability inventory: Cloud CLI execution (aws, az) for architectural validation.
  • Sanitization: No explicit content filtering or validation for external input is specified.- [METADATA_POISONING]: There is an inconsistency between the author listed in the YAML frontmatter (Jeffallan) and the platform-provided author context (seltherpython). While this is a metadata mismatch, no deceptive or malicious intent was identified in the content itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — cloud-architect