software-architecture
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE] (SAFE): The skill consists entirely of instructional markdown content focused on architectural principles and code style. No scripts, commands, or automated tasks are included.
- [EXTERNAL_DOWNLOADS] (LOW): The skill promotes a 'Library-First' approach, explicitly recommending the use of third-party libraries such as 'cockatiel', 'Redux', and 'Zustand'. While these are legitimate packages, the instruction to search npm for solutions introduces a dependency surface that relies on the agent's ability to verify external sources.
- [PROMPT_INJECTION] (LOW): As a coding assistant skill, it is intended to ingest and analyze user-provided code and architecture. This represents an indirect prompt injection surface. However, the skill lacks the capabilities (e.g., file writing, network requests) to be exploited directly, and no evidence of intentional bypass logic was found.
Audit Metadata