quality-manager-qms-iso13485

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a well-structured compliance toolkit. Analysis of all script files, reference documents, and metadata indicates no evidence of malicious activity.
  • [COMMAND_EXECUTION]: The provided Python script scripts/qms_audit_checklist.py is a utility that generates text-based checklists. It uses only standard libraries (argparse, json, sys, datetime) and does not perform network operations, file system modifications, or dynamic code execution.
  • [DATA_EXFILTRATION]: No patterns of data exfiltration were found. The skill does not contain hardcoded credentials, sensitive file paths, or network transmission capabilities.
  • [PROMPT_INJECTION]: The instructions in SKILL.md and reference files focus on task clarification and compliance workflows. There are no attempts to override safety filters or manipulate the underlying agent's core instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a minimal attack surface for indirect injection. It primarily retrieves hardcoded ISO 13485 requirements from its own reference files. User input is used as filtering criteria (e.g., selecting a clause number), which does not present a mechanism for cross-context instruction execution.
  • [OBFUSCATION]: All content is in clear text. No Base64, zero-width characters, or homoglyph-based obfuscation techniques were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:43 PM
Security Audit — agent-trust-hub — quality-manager-qms-iso13485