ra-qm-skills

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes multiple assessment tools (e.g., gdpr_compliance_checker.py and hipaa_risk_assessment.py) that analyze user-provided directories and codebases. These scripts process untrusted content and present findings back to the agent. While no specific exploit was detected, this data ingestion surface could potentially be used for indirect prompt injection if malicious instructions are embedded in files scanned by the agent. The risk is considered low as the scripts use static pattern matching and do not execute the content they analyze.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:34 PM
Security Audit — agent-trust-hub — ra-qm-skills