graphql-architect
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill contains references to a domain that is blacklisted by automated reputation scanners.\n
- Evidence: The URL 'https://jeffallan.github.io/claude-skills/skills/api-architecture/graphql-architect/' is flagged as malicious by URLite.\n- [METADATA_POISONING]: The skill file itself has been flagged for containing malware signatures.\n
- Evidence: Automated scan result 'FileRepMalware' for SKILL.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides architecture for processing external data and schemas, creating a surface for indirect prompt injection attacks.\n
- Ingestion points: Field resolvers in 'references/resolvers.md' and subgraph introspection in 'references/federation.md'.\n
- Boundary markers: The skill suggests implementing query depth limiting and complexity rules to mitigate resource exhaustion.\n
- Capability inventory: Includes 'readFileSync' for schema access and network operations for gateway-to-subgraph communication.\n
- Sanitization: Recommends using 'zod' for input validation and strict GraphQL naming conventions.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata