threat-modelling

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill maintains a restricted operational scope. It explicitly defines that it does not implement code fixes, perform penetration testing, or execute automated remediation, limiting its function to document generation.
  • [DATA_EXPOSURE]: The skill is designed to ingest infrastructure-as-code and live cloud metadata via Model Context Protocol (MCP) servers. This access is necessary for its stated purpose of architectural analysis and is governed by the user's local MCP configuration.
  • [PROMPT_INJECTION]: The skill processes external data (source code and cloud configurations) which represents a surface for indirect prompt injection. This risk is mitigated by explicit instructions to 'Confirm Before Proceeding', requiring the user to validate architecture diagrams before the agent identifies threats, and by the lack of write-access capabilities in the skill's design.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:20 AM
Security Audit — agent-trust-hub — threat-modelling