eu-nis2-expert
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an educational and advisory tool for GRC (Governance, Risk, and Compliance) professionals dealing with the EU NIS2 Directive.
- [EXTERNAL_DOWNLOADS]: The skill references framework mapping files (JSON crosswalks) hosted on GitHub Pages (
grcengclub.github.io). These resources are used to provide the underlying cybersecurity control data for the assistant and originate from the skill author's own domain. - [DATA_EXPOSURE]: No hardcoded credentials, sensitive file access, or unauthorized network operations were identified. The allowed tools (Read, Glob, Grep, Write) are appropriate for its function of analyzing project files for compliance and generating reporting artifacts.
- [PROMPT_INJECTION]: The instructions are clearly defined and lack any patterns suggesting attempts to override model safety filters or bypass initial system instructions.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided project data for assessments, the risk of indirect injection is considered low as it primarily operates as a knowledge retrieval and classification aid. Standard LLM guardrails are expected to manage risks associated with analyzing external data.
- [REMOTE_CODE_EXECUTION]: There is no evidence of scripts that download and execute code or any use of dynamic execution environments.
Audit Metadata