enterprise-vendor-management
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured procedures and templates for vendor management, selection, and risk assessment. No malicious instructions or patterns were identified.
- [SAFE]: Analysis of the TypeScript and YAML code snippets confirms they are static implementation patterns and templates, not executable malicious scripts. No unauthorized network calls or file system operations are present.
- [SAFE]: No hardcoded credentials, sensitive file paths, or obfuscated content were detected within the skill or its associated reference files.
- [INDIRECT_PROMPT_INJECTION]: The skill includes instructions for processing external data such as RFP responses and vendor assessments, which represents a potential ingestion surface. However, the skill explicitly incorporates rules for input validation and output encoding to mitigate these risks.
- Ingestion points: Processing of vendor proposals, RFI/RFP responses, and stakeholder feedback in 'Vendor Selection' and 'Performance Management' workflows.
- Boundary markers: Present; rules define explicit output formats and validation requirements.
- Capability inventory: The skill is restricted to generating text artifacts (Vendor Assessment, Contract Summary) and does not utilize file-write or network-access tools.
- Sanitization: Present; rules mandate that all inputs be validated and all outputs be encoded.
Audit Metadata