ifc-agents-migration-orchestrator

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests and processes external IFC files, which represents a surface for indirect prompt injection where malicious instructions could be embedded in metadata or string attributes.
  • Ingestion points: The skill reads the STEP HEADER section and entity instances from the IFC dataset (SKILL.md, references/methods.md).
  • Boundary markers: The process relies on structured field extraction but does not implement explicit natural language delimiters for data isolation.
  • Capability inventory: The skill uses ifcopenshell and ifcpatch for file transformation and validation routing.
  • Sanitization: The instruction set requires mandatory validation against target schemas to detect malformed or non-conformant output.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and validation services from buildingSMART and the IfcOpenShell project. These links point to well-known industry-standard domains for BIM data specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 04:40 PM
Security Audit — agent-trust-hub — ifc-agents-migration-orchestrator