compliance-auditor

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a constrained role (Compliance Auditor) focused on observing and logging rather than executing actions. The behavior is consistent with the stated purpose of decision logging and auditability.
  • [DATA_EXFILTRATION]: The skill reads a local file named REQUIREMENTS.md to establish a canonical list of requirements. This access is restricted to the local filesystem and is consistent with its stated purpose of auditing project compliance. No network exfiltration patterns or external communication were identified.
  • [PROMPT_INJECTION]: The skill processes data from the REQUIREMENTS.md file, which constitutes an ingestion point for untrusted content. While the skill lacks explicit boundary markers or sanitization for this file's content, its limited capability inventory—primarily generating text logs, tables, and metrics—minimizes the risk of indirect prompt injection. No command execution or network capabilities were found across the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 06:57 PM
Security Audit — agent-trust-hub — compliance-auditor