recsys-pipeline-architect

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external GitHub repository (github.com/mturac/recsys-pipeline-architect) for additional documentation, reference interfaces, and runnable scaffolds.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a workflow for designing systems that ingest and process external data (e.g., content feeds, search results). This introduces a surface for indirect prompt injection if the data sources contain malicious instructions. The skill's instructions for generating scaffolds do not explicitly mandate input sanitization or boundary markers, which should be implemented by the developer. Evidence chain: 1. Ingestion points: Pipeline sources and hydrators in SKILL.md. 2. Boundary markers: Not specified in scaffold instructions. 3. Capability inventory: Code generation for TypeScript, Python, and Go. 4. Sanitization: No explicit instructions for sanitizing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:58 PM
Security Audit — agent-trust-hub — recsys-pipeline-architect