ciso-advisor
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes Python scripts designed to ingest and process external JSON data, which creates an attack surface for indirect prompt injection if the source data is compromised or untrusted.
- Ingestion points: The scripts
scripts/compliance_tracker.py,scripts/risk_register_manager.py, andscripts/security_posture_scorer.pyall accept external JSON data via the--inputargument. - Boundary markers: No delimiters or specific instructions are implemented in the scripts to help an LLM distinguish between data fields and potential instruction overrides within the JSON objects.
- Capability inventory: The scripts are restricted to basic data analysis and standard output; no network operations, file system modifications, or subprocess calls were detected across any of the included files.
- Sanitization: Data ingestion relies on the standard
jsonlibrary without additional filtering or sanitization steps to detect or neutralize prompt injection payloads.
Audit Metadata