skills/timlai666/skills/eng-architect/Gen Agent Trust Hub

eng-architect

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute various environment discovery commands to identify the repository root, current branch, and the presence of specific technology stacks (e.g., Ruby, Node, Python, Go, Rust). Evidence found in SKILL.md under the preamble sections for both Eng and Design modes.
  • [PROMPT_INJECTION]: The skill contains instructions in references/agent-context-files.md that command the agent to override instructions from other skills if they conflict with its documentation management rules for CLAUDE.md and AGENTS.md. This is a localized instruction override used to enforce project standards.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing untrusted repository content to drive its behavior.
  • Ingestion points: The skill reads various repository files including *-plan.md, ARCHITECTURE.md, ENG.md, and delivery-plan.md to perform architectural analysis.
  • Boundary markers: No specific delimiters or instructions to ignore embedded instructions are provided when these files are read into the agent's context.
  • Capability inventory: The agent has access to Bash (command execution), Write/Edit (file modification), and WebSearch tools.
  • Sanitization: There is no evidence of sanitization or content validation for the ingested repository documentation files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 04:47 AM
Security Audit — agent-trust-hub — eng-architect