compliance-check

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill processes data retrieved from external tools (devtools_compliance, devtools_app) to generate compliance reports. This creates a potential surface where instructions embedded within the compliance data could influence the agent's summary or analysis.
  • Ingestion points: External data enters the agent context via tool calls for compliance status, basic app settings, and Data Protection Officer information in SKILL.md workflow steps 2 and 3.
  • Boundary markers: The instructions do not explicitly define delimiters or provide specific guidance to the agent to disregard instructions that might be contained within the processed compliance data.
  • Capability inventory: The skill is limited to information retrieval and reporting; it does not include tools for arbitrary file system writes, network exfiltration of user data, or system command execution.
  • Sanitization: There is no mention of explicit sanitization or filtering of the content returned by the developer tools before it is interpolated into the final report structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 05:03 AM