isms-audit-expert

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill and its included Python script (isms_audit_scheduler.py) were thoroughly analyzed for security risks. The tool operates locally without external network dependencies and uses standard Python libraries. No patterns of credential theft, remote code execution, or obfuscation were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill maintains a standard attack surface related to its core function of processing external audit evidence and control data.
  • Ingestion points: The skill is designed to ingest and review user-provided audit evidence and CSV files containing control risk ratings.
  • Boundary markers: The instructions do not define specific prompt delimiters for separating untrusted data from the core instructions.
  • Capability inventory: The skill can write formatted audit plans to the filesystem via the scheduler script and generate structured reports within the agent context.
  • Sanitization: Input data from CSV files is processed without explicit sanitization, which is typical for a local productivity utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:33 PM
Security Audit — agent-trust-hub — isms-audit-expert