ciso-advisor

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes Python scripts designed to ingest and process external JSON data, which creates an attack surface for indirect prompt injection if the source data is compromised or untrusted.
  • Ingestion points: The scripts scripts/compliance_tracker.py, scripts/risk_register_manager.py, and scripts/security_posture_scorer.py all accept external JSON data via the --input argument.
  • Boundary markers: No delimiters or specific instructions are implemented in the scripts to help an LLM distinguish between data fields and potential instruction overrides within the JSON objects.
  • Capability inventory: The scripts are restricted to basic data analysis and standard output; no network operations, file system modifications, or subprocess calls were detected across any of the included files.
  • Sanitization: Data ingestion relies on the standard json library without additional filtering or sanitization steps to detect or neutralize prompt injection payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:37 PM
Security Audit — agent-trust-hub — ciso-advisor