quality-manager-qms-iso13485
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a well-structured compliance toolkit. Analysis of all script files, reference documents, and metadata indicates no evidence of malicious activity.
- [COMMAND_EXECUTION]: The provided Python script
scripts/qms_audit_checklist.pyis a utility that generates text-based checklists. It uses only standard libraries (argparse,json,sys,datetime) and does not perform network operations, file system modifications, or dynamic code execution. - [DATA_EXFILTRATION]: No patterns of data exfiltration were found. The skill does not contain hardcoded credentials, sensitive file paths, or network transmission capabilities.
- [PROMPT_INJECTION]: The instructions in
SKILL.mdand reference files focus on task clarification and compliance workflows. There are no attempts to override safety filters or manipulate the underlying agent's core instructions. - [INDIRECT_PROMPT_INJECTION]: The skill has a minimal attack surface for indirect injection. It primarily retrieves hardcoded ISO 13485 requirements from its own reference files. User input is used as filtering criteria (e.g., selecting a clause number), which does not present a mechanism for cross-context instruction execution.
- [OBFUSCATION]: All content is in clear text. No Base64, zero-width characters, or homoglyph-based obfuscation techniques were detected.
Audit Metadata