enterprise-vendor-management

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured procedures and templates for vendor management, selection, and risk assessment. No malicious instructions or patterns were identified.
  • [SAFE]: Analysis of the TypeScript and YAML code snippets confirms they are static implementation patterns and templates, not executable malicious scripts. No unauthorized network calls or file system operations are present.
  • [SAFE]: No hardcoded credentials, sensitive file paths, or obfuscated content were detected within the skill or its associated reference files.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions for processing external data such as RFP responses and vendor assessments, which represents a potential ingestion surface. However, the skill explicitly incorporates rules for input validation and output encoding to mitigate these risks.
    • Ingestion points: Processing of vendor proposals, RFI/RFP responses, and stakeholder feedback in 'Vendor Selection' and 'Performance Management' workflows.
    • Boundary markers: Present; rules define explicit output formats and validation requirements.
    • Capability inventory: The skill is restricted to generating text artifacts (Vendor Assessment, Contract Summary) and does not utilize file-write or network-access tools.
    • Sanitization: Present; rules mandate that all inputs be validated and all outputs be encoded.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 08:47 PM
Security Audit — agent-trust-hub — enterprise-vendor-management