soc2-gap

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: Data Exposure Surface: The skill instructions designate sensitive files as prerequisites for analysis, including .env files, credentials, secrets, and IAM policies. Accessing these files is required for the skill's primary purpose of compliance auditing but provides the agent with access to potentially sensitive organizational data.
  • [DATA_EXFILTRATION]: Risk Mitigation: The skill includes strong counter-measures, explicitly instructing the agent to 'Never exfiltrate data' and to redact or generically reference any sensitive values found during the analysis. Additionally, the skill's allowed tools are restricted to local file reading (Read, Grep, Glob), with no network-capable tools permitted.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface:
  • Ingestion points: The skill ingests untrusted data from compliance documents, security policies, and third-party configuration files.
  • Boundary markers: The agent is instructed to treat all analyzed content as data and specifically ignore any directives like 'ignore previous instructions' embedded within those files.
  • Capability inventory: The skill is limited to analysis and reporting; it cannot execute commands or access the network.
  • Sanitization: Instructions require the agent to redact credentials and validate all final output against the provided readiness assessment schema.
  • [PROMPT_INJECTION]: Defensive Instructions: The deterministic detector flagged the use of 'ignore instructions' and similar keywords. Analysis confirms these are defensive guardrails intended to prevent the agent from being manipulated by adversarial content hidden in compliance documents, rather than an attempt to override the agent's core system prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 01:36 PM
Security Audit — agent-trust-hub — soc2-gap