qms-audit-expert

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious code, obfuscation techniques, or unauthorized network operations were detected in the provided files. The skill appears to be a legitimate professional tool for quality auditing.- [COMMAND_EXECUTION]: The skill mentions and utilizes local Python scripts (e.g., audit-prep-checklist.py, nonconformity-tracker.py) for automating audit tasks such as schedule optimization and finding tracking. These scripts are internal to the skill and support its primary auditing function.- [PROMPT_INJECTION]: The skill is designed to analyze audit data and performance metrics, which serves as a potential surface for indirect prompt injection. 1. Ingestion points: Previous audit results and process performance data (identified in SKILL.md). 2. Boundary markers: None identified. 3. Capability inventory: Execution of local scripts (scripts/*.py) for data processing. 4. Sanitization: None identified. This surface is necessary for the skill's primary objective as an audit expert.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 01:02 PM
Security Audit — agent-trust-hub — qms-audit-expert