architect-init

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local bash and PowerShell scripts (setup-architect.sh, setup-architect.ps1) to analyze the codebase. These scripts use standard system utilities to perform file and directory scans.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes untrusted codebase data (code, comments, configuration) to infer architectural decisions. This risk is mitigated by explicit instructions for the AI to provide evidence, report confidence levels, and undergo a mandatory human validation phase using the /architect-clarify command.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 03:14 PM
Security Audit — agent-trust-hub — architect-init