cmmc-expert

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external project documentation (such as System Security Plans, policies, and contracts) using tools like Read, Glob, and Grep. This creates a surface where instructions hidden within analyzed documents could potentially influence the agent's behavior.
  • Ingestion points: External project files and documentation accessed through the Read, Glob, and Grep tools (SKILL.md).
  • Boundary markers: The skill does not explicitly instruct the agent to use boundary markers, delimiters, or safety instructions (e.g., "ignore embedded instructions") when processing external content.
  • Capability inventory: The skill allows Write operations, enabling the agent to modify or create files on the filesystem based on the analysis of potentially untrusted data.
  • Sanitization: No explicit sanitization, validation, or filtering of the ingested content is specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:27 PM
Security Audit — agent-trust-hub — cmmc-expert