entity-compliance

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [SAFE]: No malicious patterns or unauthorized activity detected. The skill proactively implements formula injection defense for exported data.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from compliance reports in Mode 3b, presenting an indirect prompt injection surface. However, the agent's capabilities are limited to local file updates, and it lacks tools for network access or system command execution. Ingestion points: External reports in Mode 3b; Boundary markers: None; Capability inventory: Local file read/write; Sanitization: CSV formula neutralization.
  • [DATA_EXFILTRATION]: The skill manages sensitive corporate data in CLAUDE.md. This data stays within the local environment and is only exported via user-initiated actions; no exfiltration to remote domains was observed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — entity-compliance