c3-alter
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION] (LOW): The skill uses
lsto check for the existence of provisioned components in Stage 2b andmvto promote files in Stage 6. These are standard file management operations within the skill's defined.c3/workspace. - [DATA_EXPOSURE & EXFILTRATION] (SAFE): No sensitive file paths or network operations were identified. The file access is restricted to the architectural documentation folder (
.c3/). - [EXTERNAL_DOWNLOADS] (SAFE): No external dependencies or remote script downloads are present.
- [PROMPT_INJECTION] (SAFE): The instructions focus on a rigorous 'Architecture Decision Record' (ADR) workflow. While it uses strong instructional language ('REQUIRED', 'CRITICAL', 'MUST'), these serve to enforce the workflow steps rather than bypass safety filters.
Audit Metadata