graphql-architect

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses standard instructional language to define a persona and role. No evidence of safety filter bypasses, instruction overrides, or system prompt extraction attempts was found.
  • [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network operations were identified. The reference to resources/implementation-playbook.md is a local documentation reference.
  • [EXTERNAL_DOWNLOADS]: The skill does not contain any commands to download external scripts or install third-party packages at runtime.
  • [COMMAND_EXECUTION]: There are no shell commands or subprocess execution patterns present in the instructions.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests business requirements as input, it lacks exploitable capabilities like file-writing or network operations that could be leveraged by an indirect injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:34 PM
Security Audit — agent-trust-hub — graphql-architect