visual-architect
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: Extensive analysis confirms the skill does not contain malicious code, hidden URLs, or unauthorized system commands. It operates strictly within the domain of text transformation.
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted text from research papers, which is a vector for indirect prompt injection. However, the potential impact is eliminated by the fact that the skill has no functional capabilities beyond text generation. Evidence: 1. Ingestion points: Research paper text (SKILL.md). 2. Boundary markers: The skill does not use specific delimiters to isolate user-provided content. 3. Capability inventory: No tools, network access, or file operations are defined or accessible. 4. Sanitization: User input is processed without explicit sanitization or filtering.
Audit Metadata