architecture-refiner

Pass

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill performs its stated function of facilitating architectural discussions and documenting the results.
  • [DATA_EXPOSURE]: The skill reads repository structure and local configuration files (.lattice/config.yaml) to gather context. This is a legitimate functional requirement for an architecture tool and does not involve exfiltration to external services.
  • [COMMAND_EXECUTION]: No shell command execution or dynamic context injection patterns were found in the skill instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository (file names, directory structure, existing documentation) to inform its suggestions. While this creates a theoretical surface for indirect prompt injection, the risk is negligible within the context of an architecture refinement tool, and the skill includes no dangerous capabilities that could be triggered by such an injection.
Audit Metadata
Risk Level
SAFE
Analyzed
May 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — architecture-refiner