access-review

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes defensive instructions to detect and ignore prompt injection attempts within analyzed data. A static detection hit for instruction override was found to be a false positive, as it is actually a security mitigation instruction.
  • [PROMPT_INJECTION]: The skill processes untrusted IAM metadata and role descriptions. It implements strong boundary markers and instructions to mitigate indirect prompt injection. Evidence Chain: 1. Ingestion points: target-file argument and Read tool. 2. Boundary markers: Present in Injection Hardening and Safety Notice sections. 3. Capability inventory: Limited to Read, Grep, Glob tools. 4. Sanitization: Instructions to treat data as untrusted and ignore embedded directives.
  • [DATA_EXFILTRATION]: The skill lacks network tools and includes explicit directives prohibiting the external transfer of sensitive information discovered during audits.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:11 PM
Security Audit — agent-trust-hub — access-review