domain-decomposition-api-design-advisor

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely composed of text-based instructions for architectural modeling and domain decomposition. It does not include any executable code, scripts, or external dependencies.- [PROMPT_INJECTION]: No attempts to bypass safety filters, override system instructions, or extract system prompts were found. The instructional language is standard for a design advisor.- [DATA_EXFILTRATION]: There are no network requests, API calls, or commands that access sensitive files such as environment variables or credentials.- [COMMAND_EXECUTION]: No shell commands, subprocess calls, or system-level operations are defined or requested within the skill files.- [INDIRECT_PROMPT_INJECTION]: * Ingestion points: The skill gathers business goals, user journeys, and technical constraints as external input in the 'Inputs To Gather' section of SKILL.md. * Boundary markers: No explicit delimiters or instructions to ignore embedded commands in the input data are provided. * Capability inventory: The skill has no access to tools, scripts, or file-writing capabilities. * Sanitization: No sanitization or validation of the input data is performed. * Evaluation: While the skill lacks input boundaries, the absence of any exploitable capabilities (such as code execution or network access) ensures there is no functional risk from indirect injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 03:28 PM
Security Audit — agent-trust-hub — domain-decomposition-api-design-advisor