architect
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The agent implements a self-evolution loop (the 'evolve' recipe) that enables it to modify its own instructions in SKILL.md and update files in the reference/ directory. This process, detailed in reference/self-evolution.md, includes a safety framework with autonomous update levels (A and B) and rollback mechanisms. However, the ability for an agent to rewrite its own operating instructions at runtime constitutes a dynamic execution pattern.
- [INDIRECT_PROMPT_INJECTION]: The skill manages a workflow where user-supplied requirements are used to generate new agent skills and documentation.
- Ingestion points: User-provided goals and requirements are ingested during the UNDERSTAND phase of the design workflow (SKILL.md).
- Boundary markers: The skill relies on explicit Always/Ask First/Never rules and role boundaries defined in _common/BOUNDARIES.md.
- Capability inventory: The skill generates and writes files (SKILL.md and reference files) to the local filesystem.
- Sanitization: Generated outputs are validated against the reference/validation-checklist.md and reviewed via the Judge partner feedback loop.
Audit Metadata