code-to-control-mapper
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a Node.js script located at
plugins/grc-engineer/scripts/map-control.js. This script is a vendor-owned resource belonging to the skill's author context and is utilized for the primary purpose of analyzing configuration files. - [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for processing external data by reading and analyzing infrastructure-as-code files (Terraform, Kubernetes, etc.). This is consistent with its stated purpose as a compliance mapping tool and includes standard file read operations.
Audit Metadata