prompt-governance
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted prompt text to perform safety audits and catalog management, representing a surface area for indirect prompt injection. This behavior is expected for the skill's primary governance function.\n
- Ingestion points: External content is ingested through the
prompt_auditor.pyandprompt_catalog_manager.pyscripts via file, stdin, or direct text parameters.\n - Boundary markers: The skill does not implement explicit delimiters or instruction-isolation markers when processing the target prompt data.\n
- Capability inventory: The skill possesses file system capabilities, including reading target files and writing versioned prompt files and a JSON catalog via
prompt_catalog_manager.py.\n - Sanitization: No sanitization or escaping is applied to the processed prompts beyond identifying patterns during the audit process.
Audit Metadata