sruja-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions and helper scripts to download the Sruja CLI installation script from the vendor's official domain (
sruja.ai). - [REMOTE_CODE_EXECUTION]: The skill documents and automates the execution of a remote installation script via
curl | bash. This is the official installation method provided by the skill's author for their tool. - [COMMAND_EXECUTION]: The skill frequently invokes local shell commands using the
srujaCLI (e.g.,sruja discover,sruja sync,sruja lint,sruja drift) to perform static analysis and architecture validation on the codebase. - [PERSISTENCE]: The skill implements a mechanism for "Auto-Capturing Knowledge" where the agent is instructed to record user-defined patterns and conventions into a local file (
.sruja/agent_memory.json). This information is retrieved in subsequent sessions via thesruja_record_learningtool to maintain context. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill ingests untrusted codebase metadata, such as module imports and dependency graphs, through
sruja discoverand.sruja/author_evidence.json(found inSKILL.mdandREFERENCE.md). - Boundary markers: The instructions include explicit guardrails for the agent, such as "No guessing," prioritizing evidence-first modeling, and marking ambiguities with "OPEN QUESTIONS" blocks.
- Capability inventory: The skill has the capability to execute shell commands via the CLI and write architecture proposals to the filesystem.
- Sanitization: The skill utilizes
sruja lintto programmatically validate the generated DSL and ensure it conforms to structural and governance rules.
Audit Metadata