semantic-core-architect
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill operates entirely on local project data and predefined YAML templates. It does not perform any network operations or access sensitive system files.
- [COMMAND_EXECUTION]: The skill includes instructions to run local Python linter scripts (lint_production_skill.py and lint_skill_cluster.py) for validating the generated semantic core artifacts. These are standard development tools and do not pose a security risk in this context.
- [SAFE]: The skill incorporates a robust validation process and a detailed rubric, which helps prevent the injection of malicious or unverified information into the site's architecture. Ingestion points: Site goals and audience (SKILL.md); Boundary markers: YAML templates (assets/); Capability inventory: local linting scripts (SKILL.md); Sanitization: rubric-enforced metric validation (references/semantic-core-rubric.md).
Audit Metadata