code-to-control-mapper

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a Node.js script located at plugins/grc-engineer/scripts/map-control.js. This script is a vendor-owned resource belonging to the skill's author context and is utilized for the primary purpose of analyzing configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for processing external data by reading and analyzing infrastructure-as-code files (Terraform, Kubernetes, etc.). This is consistent with its stated purpose as a compliance mapping tool and includes standard file read operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:26 PM
Security Audit — agent-trust-hub — code-to-control-mapper