regulatory-affairs-head
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured regulatory strategy and submission guidance for MedTech products. All resources, including scripts and reference documents, are locally contained within the skill and belong to the skill author.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests product and market data from stakeholders for regulatory planning and status tracking. While this creates a data ingestion surface, the capability is limited to local file storage and is essential to the skill's primary tracking purpose. * Ingestion points: Stakeholder inputs regarding device classification, intended use, and target markets gathered in the strategy workflow. * Boundary markers: The workflows do not explicitly implement delimiters or specific instructions for the agent to ignore potentially malicious embedded content in user-provided regulatory data. * Capability inventory: The 'scripts/regulatory_tracker.py' tool possesses file-write capability to manage the 'regulatory_submissions.json' data file. * Sanitization: The tracking script uses standard JSON serialization for data storage and does not include custom sanitization or validation logic for the input strings.
Audit Metadata