architecture-compass

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: Detailed inspection of the 183 markdown and configuration files confirms the skill is a legitimate tool for managing Architecture Decision Records (ADRs). It contains no executable scripts, hidden logic, or malicious instructions.
  • [NO_CODE]: The skill provides guidance and templates but does not distribute executable runtime code, significantly limiting its direct attack surface.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill incorporates specific defensive records (AC-ADR-004, AC-ADR-019, AC-ADR-020) that mandate the protection of secrets and personal data, and it explicitly forbids the exposure of credentials in logs or artifacts.
  • [REMOTE_CODE_EXECUTION]: Guidelines within the skill (AC-ADR-033, AC-ADR-038) define strict boundaries for tool installation and provider usage, requiring explicit user selection and approval for any external or state-changing operations.
  • [INDIRECT_PROMPT_INJECTION]: The framework is designed to mitigate injection risks by treating all retrieved content, model outputs, and third-party data as untrusted input and enforcing validated trust boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:30 PM
Security Audit — agent-trust-hub — architecture-compass