isms-audit-expert
Pass
Audited by Gen Agent Trust Hub on Mar 15, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest untrusted data from ISMS documentation and technical security reports, which could contain malicious instructions. * Ingestion points: Policy reviews and technical assessment outputs mentioned in SKILL.md. * Capability inventory: Mentions of automated testing and reporting scripts. * Boundary markers: Lack of explicit instructions for the model to ignore instructions found within processed data. * Sanitization: No defined sanitization or validation for external content.
- [NO_CODE]: Several functional components mentioned in the documentation, such as 'security-control-tester.py' and 'external-pentest-guide.md', are missing from the skill package, which contains only placeholder files.
Audit Metadata