iso-standards-readiness
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill contains references to official standards and regulatory websites, including ISO (iso.org), the FDA (fda.gov), and the European Commission (europa.eu). These references are purely informational for bibliographic and guidance purposes and do not involve automated code retrieval or execution.
- [DATA_EXFILTRATION]: All bundled Python scripts are restricted to the standard library and perform no network operations. File system interactions are limited to reading local user-provided inputs and writing reports to user-specified paths, with built-in protections against symbolic links and path traversal in the evidence verification logic.
- [DYNAMIC_EXECUTION]: The skill does not use dangerous dynamic evaluation functions such as
eval(),exec(), or unsafe deserialization likepickle. JSON processing includes security-conscious limits on nesting depth, item counts, and payload size to prevent resource exhaustion. - [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing user-supplied JSON evidence manifests. This ingestion is protected by strict structural validation and deterministic scripts. The instructions to the agent explicitly require treating all outputs as drafts for human review and prohibit the agent from making autonomous compliance or safety determinations.
Audit Metadata