soc2-gap
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill incorporates defensive instructions to disregard directives found within analyzed content. It also possesses a surface for indirect prompt injection. Ingestion points: Data provided via $ARGUMENTS and files read using Read, Grep, and Glob tools. Boundary markers: Explicit instructions in the Prompt Injection Safety Notice to treat embedded text as data. Capability inventory: Restrictive toolset with no network or code execution access. Sanitization: Instructions to redact credentials and sensitive tokens from reports.
- [DATA_EXFILTRATION]: The skill audits sensitive infrastructure configurations but includes mandatory data protection rules that prevent the leakage of raw credentials or API keys in the final output.
Audit Metadata