drata-inspector-expert
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists solely of informational markdown content. There are no executable scripts, shell commands, or tool definitions present in the provided file.
- [INDIRECT_PROMPT_INJECTION]: The skill instructions involve interpreting external JSON findings stored in
~/.cache/claude-grc/findings/drata-inspector/. This creates a theoretical attack surface for indirect prompt injection, although the skill lacks the capabilities to perform automated actions that could be exploited. - Ingestion points: Processes JSON findings located at
~/.cache/claude-grc/findings/drata-inspector/<run_id>.json. - Boundary markers: The instructions do not specify any delimiters or warnings to ignore embedded instructions within the processed data.
- Capability inventory: No scripts, subprocess calls, or network operations are defined within this skill.
- Sanitization: There are no instructions for validating, escaping, or filtering the input JSON data before processing.
Audit Metadata