grc-third-party-risk-diagram

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external business data (vendor information, workflows) which represents an indirect prompt injection surface.
  • Ingestion points: Processes user-supplied vendor details, questionnaire workflows, and organizational roles (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or 'ignore embedded instructions' markers for user-provided data.
  • Capability inventory: Access to Write, Bash, Read, and WebFetch tools (SKILL.md frontmatter).
  • Sanitization: No explicit sanitization or validation of the input data is described before use with the diagram generation tools.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the draw.io CLI via the Bash tool for exporting diagrams when available. This is consistent with the skill's primary purpose and does not involve execution of arbitrary or malicious commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:26 PM
Security Audit — agent-trust-hub — grc-third-party-risk-diagram