risk-register-manager

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of external data files stored in the ./grc-data/risks/ directory.
  • Ingestion points: The agent reads JSON and YAML files from the ./grc-data/risks/ path to perform assessments and generate reports.
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from obeying instructions embedded within the risk data files.
  • Capability inventory: The skill utilizes 'Read', 'Write', and 'Glob' tools to interact with the file system.
  • Sanitization: No sanitization or validation logic is specified to filter or escape potentially malicious natural language instructions within the risk descriptions or metadata fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:26 PM
Security Audit — agent-trust-hub — risk-register-manager