nist-csf-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes assessment data from user-controlled JSON files which are then reflected in Markdown and JSON reports, creating a potential injection vector if the output is subsequently processed by an AI agent.
- Ingestion points: The
scripts/csf_maturity_assessor.pyscript reads organizational assessment data, including evidence and notes, from a JSON file specified by the--inputargument. - Boundary markers: The script does not use specific delimiters or instructions to prevent the AI from interpreting instructions embedded within the processed text fields.
- Capability inventory: The script performs file writing operations to save assessment results and remediation roadmaps. It does not have network access or administrative execution capabilities.
- Sanitization: The script performs data type and range validation on maturity scores but does not sanitize the contents of the
evidenceandnotesstring fields, which are directly included in the final report output.
Audit Metadata