compliance-check
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill processes data retrieved from external tools (
devtools_compliance,devtools_app) to generate compliance reports. This creates a potential surface where instructions embedded within the compliance data could influence the agent's summary or analysis. - Ingestion points: External data enters the agent context via tool calls for compliance status, basic app settings, and Data Protection Officer information in
SKILL.mdworkflow steps 2 and 3. - Boundary markers: The instructions do not explicitly define delimiters or provide specific guidance to the agent to disregard instructions that might be contained within the processed compliance data.
- Capability inventory: The skill is limited to information retrieval and reporting; it does not include tools for arbitrary file system writes, network exfiltration of user data, or system command execution.
- Sanitization: There is no mention of explicit sanitization or filtering of the content returned by the developer tools before it is interpolated into the final report structure.
Audit Metadata