clean-architecture
Pass
Audited by Gen Agent Trust Hub on Feb 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard architectural patterns and Java code templates for implementing clean, hexagonal architectures. No malicious code, obfuscation, or safety bypass patterns were detected.
- [EXTERNAL_DOWNLOADS]: Mentions well-known and trusted Java ecosystem libraries including Spring Boot, MapStruct, Lombok, and Testcontainers. It references official Docker images such as PostgreSQL 16 for integration testing examples. These are considered safe and well-known services.
- [COMMAND_EXECUTION]: Requested tool permissions (Bash, Write, Edit) are necessary and proportionate for the skill's purpose of scaffolding and refactoring backend application codebases.
- [PROMPT_INJECTION]: Identified a vulnerability surface for indirect prompt injection because the skill involves reading external project files using high-privilege tools. Ingestion points: Local source code and configuration files via the Read and Grep tools. Boundary markers: No explicit markers or delimiters are defined in the instructions to separate data from instructions during ingestion. Capability inventory: Significant capabilities including Write, Edit, and Bash. Sanitization: No specific sanitization or content validation logic is described for the files processed.
Audit Metadata