drata-inspector-expert

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists solely of informational markdown content. There are no executable scripts, shell commands, or tool definitions present in the provided file.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions involve interpreting external JSON findings stored in ~/.cache/claude-grc/findings/drata-inspector/. This creates a theoretical attack surface for indirect prompt injection, although the skill lacks the capabilities to perform automated actions that could be exploited.
  • Ingestion points: Processes JSON findings located at ~/.cache/claude-grc/findings/drata-inspector/<run_id>.json.
  • Boundary markers: The instructions do not specify any delimiters or warnings to ignore embedded instructions within the processed data.
  • Capability inventory: No scripts, subprocess calls, or network operations are defined within this skill.
  • Sanitization: There are no instructions for validating, escaping, or filtering the input JSON data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 09:57 AM
Security Audit — agent-trust-hub — drata-inspector-expert