sop-builder
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill focuses exclusively on documentation tasks and Mermaid diagram generation, with no instructions or tools related to network exfiltration, persistence, or privilege escalation.
- [PROMPT_INJECTION]: The skill processes untrusted structured data (JSON and XML) from external files, which represents an indirect prompt injection surface. This is mitigated by robust documentation principles that require the agent to stick to factual source information and explicitly state when information is not defined.
- [SAFE]: The 'Quality Standards' section provides a security control by instructing the agent to avoid hallucinations and assumptions, which prevents the agent from being led into non-functional or speculative behaviors by malformed or malicious inputs in the workflow specifications.
Audit Metadata