reviewing-security-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of markdown documentation and instructional guidelines. It does not contain any executable scripts, shell commands, or automated tasks.
- [PROMPT_INJECTION]: The instructions are focused on architectural review criteria and do not include patterns designed to bypass agent safety constraints or extract system prompts.
- [DATA_EXPOSURE]: No hardcoded secrets, API keys, or sensitive local file paths were detected. The skill does not perform any network requests.
- [EXTERNAL_DOWNLOADS]: There are no references to external package managers (npm, pip) or remote script execution patterns (curl/wget to bash).
- [OBFUSCATION]: The content was scanned for hidden characters, Base64 encoding, and homoglyph attacks; no obfuscated URLs or malicious patterns were found.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to analyze user-provided system designs (untrusted data), it lacks high-risk capabilities such as file-writing or network access that would allow for an exploitation chain.
Audit Metadata