qms-audit-expert
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious code, obfuscation techniques, or unauthorized network operations were detected in the provided files. The skill appears to be a legitimate professional tool for quality auditing.- [COMMAND_EXECUTION]: The skill mentions and utilizes local Python scripts (e.g.,
audit-prep-checklist.py,nonconformity-tracker.py) for automating audit tasks such as schedule optimization and finding tracking. These scripts are internal to the skill and support its primary auditing function.- [PROMPT_INJECTION]: The skill is designed to analyze audit data and performance metrics, which serves as a potential surface for indirect prompt injection. 1. Ingestion points: Previous audit results and process performance data (identified inSKILL.md). 2. Boundary markers: None identified. 3. Capability inventory: Execution of local scripts (scripts/*.py) for data processing. 4. Sanitization: None identified. This surface is necessary for the skill's primary objective as an audit expert.
Audit Metadata