whistleblower-compliance
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides tools for regulatory compliance assessment and policy generation. It operates locally using standard Python scripts included in the repository.
- [COMMAND_EXECUTION]: The skill uses two Python scripts (
scripts/whistleblower_compliance_checker.pyandscripts/whistleblower_policy_scaffolder.py) which process user-provided arguments (e.g., headcount, jurisdiction, sector). These scripts use the standardargparselibrary and do not perform any dangerous operations such as shell execution of untrusted data, remote downloads, or credential harvesting. - [INDIRECT_PROMPT_INJECTION]: The skill ingests organizational metadata (name, headcount, sector) to populate policy templates and calculate compliance scores. These inputs are used purely for text generation and scoring logic within the Python scripts; there is no evidence of the data being used to influence agent behavior or bypass safety guardrails.
- [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or non-whitelisted network operations were found. The scripts operate on input parameters provided via the CLI and do not access system secrets.
Audit Metadata