soc2-compliance-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied JSON data to generate compliance reports and track audit evidence, which presents a surface for indirect prompt injection if the processed data contains malicious instructions.
- Ingestion points: The scripts
soc2_readiness_checker.py,evidence_collector.py, andsoc2_infrastructure_auditor.pyingest data from files provided via the--configand--statusarguments. - Boundary markers: The scripts do not use explicit delimiters or "ignore embedded instructions" warnings for the natural language fields (such as
notesordescription) within the JSON files. - Capability inventory: Across all files, the capabilities are limited to local filesystem read/write operations for configuration and tracking files. No network operations or arbitrary command execution were found in the scripts.
- Sanitization: There is no evidence of filtering or sanitization of string values within the processed JSON files.
Audit Metadata