improve-codebase-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it is designed to ingest and interpret untrusted data from a codebase to perform architectural reviews.
- Ingestion points: The skill reads
CONTEXT.md,docs/adr/files, and uses an exploration agent to walk the codebase as described inSKILL.md. - Boundary markers: Absent. The instructions do not define specific delimiters or "ignore" instructions to separate codebase content from the agent's internal logic.
- Capability inventory: The skill has the ability to read and write files (creating or updating
CONTEXT.mdand ADRs) and can spawn sub-agents to perform design tasks. - Sanitization: Absent. Data read from the repository is interpolated into the reasoning process without explicit sanitization or filtering of potential instructions embedded in the code or comments.
Audit Metadata