architecture-compass
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: Detailed inspection of the 183 markdown and configuration files confirms the skill is a legitimate tool for managing Architecture Decision Records (ADRs). It contains no executable scripts, hidden logic, or malicious instructions.
- [NO_CODE]: The skill provides guidance and templates but does not distribute executable runtime code, significantly limiting its direct attack surface.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill incorporates specific defensive records (AC-ADR-004, AC-ADR-019, AC-ADR-020) that mandate the protection of secrets and personal data, and it explicitly forbids the exposure of credentials in logs or artifacts.
- [REMOTE_CODE_EXECUTION]: Guidelines within the skill (AC-ADR-033, AC-ADR-038) define strict boundaries for tool installation and provider usage, requiring explicit user selection and approval for any external or state-changing operations.
- [INDIRECT_PROMPT_INJECTION]: The framework is designed to mitigate injection risks by treating all retrieved content, model outputs, and third-party data as untrusted input and enforcing validated trust boundaries.
Audit Metadata