architecture-compass
Pass
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill analyzes untrusted repository files, creating a surface for indirect prompt injection where malicious code comments could influence the agent's behavior.
- Ingestion points: Processes up to 25 files from the repository, including dependency manifests (e.g., package.json, pom.xml) and source code entry points.
- Boundary markers: No specific delimiters or 'ignore embedded instructions' warnings are used when the agent reads external code files.
- Capability inventory: The skill is capable of reading repository files and writing a summary insights document to .lattice/insights/architecture.md.
- Sanitization: Extracted code signals and file contents are not sanitized before being summarized into the final report.
Audit Metadata