compliance-tracker
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's functionality is consistent with its stated purpose of GRC monitoring. The instructions focus on analyzing compliance data and generating reports.
- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes external compliance documents, audit reports, and evidence folders. This is inherent to the skill's primary function. \n
- Ingestion points: Local compliance documentation repositories, evidence folders, and audit reports. \n
- Boundary markers: None specified in the instructions to delimit untrusted data. \n
- Capability inventory: Access is limited to Read, Glob, Grep, and Write tools. \n
- Sanitization: No specific sanitization or filtering of external content is described.
Audit Metadata