quality-nonconformance
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for processing data from external, untrusted sources, which creates a surface for indirect prompt injection attacks.
- Ingestion points: The skill handles data from customer complaints, supplier portals, and incoming inspection reports as described in the 'NCR Lifecycle' and 'CAPA System' sections of SKILL.md.
- Boundary markers: There are no delimiters or specific instructions to the agent to ignore potentially malicious instructions embedded in the ingested data.
- Capability inventory: The skill consists only of text instructions and does not define any scripts, binaries, or tool calls in SKILL.md.
- Sanitization: The skill does not provide any methods for sanitizing or validating the untrusted data it processes.
- [NO_CODE]: The skill consists entirely of markdown instructions and YAML metadata. It does not include any executable scripts, source code, or references to external software packages.
Audit Metadata