architect
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted data from the repository and generated design candidates to synthesize its final output.\n
- Ingestion points: Repository files containing behavior, history, and conventions (SKILL.md, Step 2); output from independent design candidates (SKILL.md, Step 5).\n
- Boundary markers: No explicit delimiter or instruction to ignore instructions within the grounded evidence or candidates is specified.\n
- Capability inventory: Writing design artifacts to the file system (SKILL.md, Step 8) and executing experiments (SKILL.md, Step 2).\n
- Sanitization: No evidence of validation or sanitization for ingested repository content or candidate designs.
Audit Metadata