agile-v-compliance

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional documentation for compliance management. No executable scripts, network calls, or unauthorized file access patterns were identified. The content aligns with the stated purpose of risk management and auditing.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions define processes for reading and writing to various compliance logs, creating a potential data ingestion surface.
  • Ingestion points: Files including .agile-v/RISK_REGISTER.md, .agile-v/CAPA_LOG.md, .agile-v/APPROVALS.md, and .agile-v/CHECKPOINTS.md are updated and reviewed based on the instructions.
  • Boundary markers: The instructions mandate strict, structured table formats (e.g., specific columns for risk IDs and CAPA triggers) which help differentiate data from potential instructions.
  • Capability inventory: No code execution, network capabilities, or dangerous subprocesses are defined within this skill file.
  • Sanitization: No explicit sanitization or filtering logic is provided, though the requirement for human approval at various 'Gates' serves as a manual control.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:07 AM
Security Audit — agent-trust-hub — agile-v-compliance