grc-risk-treatment-diagram
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill body consists of instructional guidelines for GRC workflow visualization. No malicious patterns, exfiltration attempts, or obfuscated payloads were identified.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as an ingestion point for user-supplied risk scenarios (Ingestion points: Common Requests section in SKILL.md) which are then processed using tools to generate diagrams (Capability inventory: Write, Bash, Read, WebFetch). There are no defined boundary markers or specific sanitization routines (Sanitization: Absent) for the input data, presenting a standard indirect injection surface for this type of task.
Audit Metadata