sox-compliance
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill and its associated files are entirely consistent with the stated goal of internal audit and compliance testing. There are no attempts to access sensitive files, execute arbitrary commands, or perform network operations.\n- [PROMPT_INJECTION]: The skill processes external data (such as CSV invoice populations), creating a potential surface for indirect prompt injection.\n
- Ingestion points: The skill processes CSV populations for audit testing (e.g.,
evals/files/revenue_population.csv).\n - Boundary markers: The instructions do not provide explicit delimiters or instructions for the agent to ignore potential commands within the data files.\n
- Capability inventory: The skill facilitates data analysis, attribute verification, and reporting.\n
- Sanitization: No specific input sanitization is described for the processed datasets.\n Note: This is a low-risk surface inherent to data analysis tools and is considered safe in this context.
Audit Metadata