docs-architect
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to perform deep analysis of external codebase content, which is untrusted data. Malicious instructions hidden in comments or code within these files could potentially influence the agent's behavior.
- Ingestion points: Processes codebase files, dependencies, and implementation details as part of the 'Discovery Phase'.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the agent when reading and analyzing external code content.
- Capability inventory: The agent is required to read and summarize various files across the project directory to build architecture documentation.
- Sanitization: No methods for sanitizing, validating, or escaping instructions embedded in the target codebase are mentioned in the skill instructions.
Audit Metadata