socratic-drill

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill uses tools like Read, Glob, and Grep to access framework definitions and control lists stored locally. It does not attempt to access sensitive system files, credentials, or private keys.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (compliance frameworks and control mappings) which constitutes an ingestion surface. While malicious content could theoretically be embedded in these framework files to influence the AI's behavior, the skill's capabilities are limited to educational drilling, and it lacks the high-privilege or network-enabled tools required for significant exploitation.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform its logic, but the instructions focus on resolving framework names and mapping control IDs rather than executing arbitrary or user-supplied shell commands.
  • [SAFE]: The skill explicitly avoids persisting data to disk in its current version and follows best practices by paraphrasing normative standards instead of reproducing them, minimizing potential copyright or intellectual property exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:26 PM
Security Audit — agent-trust-hub — socratic-drill