quality-nonconformance

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for processing data from external, untrusted sources, which creates a surface for indirect prompt injection attacks.
  • Ingestion points: The skill handles data from customer complaints, supplier portals, and incoming inspection reports as described in the 'NCR Lifecycle' and 'CAPA System' sections of SKILL.md.
  • Boundary markers: There are no delimiters or specific instructions to the agent to ignore potentially malicious instructions embedded in the ingested data.
  • Capability inventory: The skill consists only of text instructions and does not define any scripts, binaries, or tool calls in SKILL.md.
  • Sanitization: The skill does not provide any methods for sanitizing or validating the untrusted data it processes.
  • [NO_CODE]: The skill consists entirely of markdown instructions and YAML metadata. It does not include any executable scripts, source code, or references to external software packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — quality-nonconformance