nis2-directive-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns detected across all 11 threat categories.
- [COMMAND_EXECUTION]: The skill includes two Python scripts (scripts/nis2_scope_analyzer.py and scripts/nis2_compliance_checker.py) intended for local execution by the user to perform compliance assessments. These scripts do not contain dangerous shell commands, subprocess calls, or unauthorized system access.
- [DATA_EXFILTRATION]: No network operations or data exfiltration patterns were identified. The scripts operate entirely on local data provided via CLI flags or JSON configuration files.
- [INDIRECT_PROMPT_INJECTION]: The skill processes organizational data via JSON files. Ingestion points: Configuration data is read in nis2_compliance_checker.py and nis2_scope_analyzer.py via the --config parameter. Boundary markers: Absent; input is expected in structured JSON format. Capability inventory: Analysis of all scripts confirms no subprocess calls, system file writes, or network operations. Sanitization: Standard json.load() is used for parsing, which prevents common code injection vectors.
Audit Metadata