atlas
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as its primary function involves the ingestion and analysis of external, potentially untrusted project data.
- Ingestion points: The agent reads and processes local repository structures, source code, and dependency manifest files such as
Cargo.toml(Rust),Package.swift(Swift), and Gradle configurations (JVM). - Boundary markers: While the skill uses structured outputs (MADR 4.0 and JSON), it does not explicitly define mandatory delimiting or 'ignore embedded instructions' markers when interpolating raw external data into its internal prompts.
- Capability inventory: The skill possesses significant capabilities, including file system read access, complex architectural report generation, and the ability to trigger downstream refactoring and implementation agents (Zen, Builder).
- Sanitization: The skill includes a robust 'grounding' phase in its multi-engine deliberation process (
reference/tri-engine-architect.md) that requires findings to be verified against repository evidence, reducing the risk of being misled by adversarial patterns in the analyzed data.
Audit Metadata