rma-assessment-assistant

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's HTML report templates load visualization libraries from a well-known content delivery network to generate interactive charts.
  • Evidence: The files assets/html-report-template.html and assets/html-report-template_zh.html include script tags for Chart.js and Mermaid.js hosted on cdn.jsdelivr.net.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data provided by the user, creating a vulnerability surface where instructions embedded in those files could influence the agent's behavior.
  • Ingestion points: The agent is instructed to read and analyze architecture documents and Infrastructure-as-Code (IaC) files (such as CloudFormation or Terraform) provided by the user, as described in references/assessment-workflow.md and references/auto-analysis-rules.md.
  • Boundary markers: The instructions do not define explicit boundary markers or delimiters to isolate user-provided file content from the agent's own task instructions.
  • Capability inventory: The skill has the capability to read files (Read, Grep, Glob) and write reports (Write) based on the analyzed data.
  • Sanitization: There is no evidence of content sanitization or instruction-filtering for the data retrieved from external files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:10 PM