sruja-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions and helper scripts to download the Sruja CLI installation script from the vendor's official domain (sruja.ai).
  • [REMOTE_CODE_EXECUTION]: The skill documents and automates the execution of a remote installation script via curl | bash. This is the official installation method provided by the skill's author for their tool.
  • [COMMAND_EXECUTION]: The skill frequently invokes local shell commands using the sruja CLI (e.g., sruja discover, sruja sync, sruja lint, sruja drift) to perform static analysis and architecture validation on the codebase.
  • [PERSISTENCE]: The skill implements a mechanism for "Auto-Capturing Knowledge" where the agent is instructed to record user-defined patterns and conventions into a local file (.sruja/agent_memory.json). This information is retrieved in subsequent sessions via the sruja_record_learning tool to maintain context.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill ingests untrusted codebase metadata, such as module imports and dependency graphs, through sruja discover and .sruja/author_evidence.json (found in SKILL.md and REFERENCE.md).
  • Boundary markers: The instructions include explicit guardrails for the agent, such as "No guessing," prioritizing evidence-first modeling, and marking ambiguities with "OPEN QUESTIONS" blocks.
  • Capability inventory: The skill has the capability to execute shell commands via the CLI and write architecture proposals to the filesystem.
  • Sanitization: The skill utilizes sruja lint to programmatically validate the generated DSL and ensure it conforms to structural and governance rules.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 01:18 PM
Security Audit — agent-trust-hub — sruja-architecture