oscal-expert

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an educational resource for OSCAL document authoring and validation. It contains no executable code, network operations, or requests for sensitive data. All external references are to official security standards and documentation repositories.
  • [PROMPT_INJECTION]: The skill directs the agent to process outputs from validation tools. Ingestion points: Error messages from 'oscal validate'. Boundary markers: The instructions provide a specific lookup table for interpreting errors. Capability inventory: Uses designated tool commands for validation and conversion. Sanitization: The agent is limited to proposing schema fixes based on defined mappings, which serves as a functional boundary against malicious payloads in tool output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:27 PM
Security Audit — agent-trust-hub — oscal-expert