c4-code

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured templates and instructions for documenting software architecture. It does not include executable code, shell commands, or external network operations.
  • [SAFE]: The skill references a local file at resources/implementation-playbook.md to provide detailed examples. This is a standard internal reference pattern and does not involve remote content loading or unauthorized file access.
  • [SAFE]: While the skill is designed to analyze local code directories, which constitutes an ingestion point for untrusted data (potential for Indirect Prompt Injection), its functionality is limited to generating documentation and Mermaid diagrams. This inherent structure acts as a constraint, and the skill does not request sensitive data or provide capabilities that would allow for data exfiltration or system modification.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 12:47 PM
Security Audit — agent-trust-hub — c4-code