ifc-impl-cobie

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection attempts was found. The instructions are focused on technical domain-specific guidance for IFC data modelling and do not attempt to override agent behavior or safety filters.
  • [DATA_EXFILTRATION]: No sensitive data exposure or exfiltration patterns detected. The skill does not access sensitive file paths, environment variables, or hardcoded credentials. All external links point to official buildingSMART documentation or placeholder domains (example.com).
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or external script downloads were detected. The skill consists entirely of markdown documentation and static data examples.
  • [COMMAND_EXECUTION]: No shell commands, subprocess invocations, or privilege escalation attempts (such as sudo or chmod) are present in the skill instructions or examples.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any automated downloads or package installations. It lists references to official industry standards bodies which are informational only.
  • [OBFUSCATION]: No obfuscation techniques were detected. The content is written in clear, plain-text markdown and standard IFC STEP syntax. GUIDs present in examples are standard IFC identifiers and do not contain hidden payloads.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes data structures but does not implement logic that ingests untrusted external data into an execution environment. It acts as a static reference for data mapping.
  • [DYNAMIC_EXECUTION]: The skill does not use dynamic execution patterns like eval, exec, or runtime compilation. All code snippets provided are non-executable STEP file data instances.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 04:39 PM
Security Audit — agent-trust-hub — ifc-impl-cobie