arize-compliance-audit

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by separating the audit phase (read-only) from the remediation phase. It explicitly instructs the agent to present a legal disclaimer and never modify code without user confirmation.
  • [PROMPT_INJECTION]: The skill ingests codebase content for analysis, which constitutes a surface for indirect prompt injection. This risk is mitigated by the skill's requirement for the agent to present findings and obtain user consent before taking any corrective actions.
  • [EXTERNAL_DOWNLOADS]: During the optional remediation phase, the skill recommends installing established and reputable security libraries such as guardrails-ai, nemo-guardrails, and presidio-analyzer. These are standard industry tools for AI safety and data protection.
  • [DATA_EXFILTRATION]: The skill searches for sensitive data (API keys, PII) to identify compliance gaps but does not perform any unauthorized network operations to exfiltrate this information. It stores audit reports locally in a temporary directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 01:03 AM
Security Audit — agent-trust-hub — arize-compliance-audit