rma-assessment-assistant
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's HTML report templates load visualization libraries from a well-known content delivery network to generate interactive charts.
- Evidence: The files
assets/html-report-template.htmlandassets/html-report-template_zh.htmlinclude script tags forChart.jsandMermaid.jshosted oncdn.jsdelivr.net. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data provided by the user, creating a vulnerability surface where instructions embedded in those files could influence the agent's behavior.
- Ingestion points: The agent is instructed to read and analyze architecture documents and Infrastructure-as-Code (IaC) files (such as CloudFormation or Terraform) provided by the user, as described in
references/assessment-workflow.mdandreferences/auto-analysis-rules.md. - Boundary markers: The instructions do not define explicit boundary markers or delimiters to isolate user-provided file content from the agent's own task instructions.
- Capability inventory: The skill has the capability to read files (
Read,Grep,Glob) and write reports (Write) based on the analyzed data. - Sanitization: There is no evidence of content sanitization or instruction-filtering for the data retrieved from external files.
Audit Metadata