customs-trade-compliance

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted trade data, including commercial invoices, certificates of origin, and bills of materials. This creates a potential surface where malicious instructions embedded in these documents could attempt to influence the agent's behavior during classification or compliance screening.
  • Ingestion points: Product specifications, commercial invoices, ISF filings, and Bill of Materials (BOM) components mentioned in the 'How It Works' and 'Decision Frameworks' sections of SKILL.md.
  • Boundary markers: No explicit instructions are provided to the agent to ignore or delimit instructions found within the processed trade data.
  • Capability inventory: The skill does not include any code, network operations, or tool invocations that could be exploited via injection.
  • Sanitization: There are no instructions for sanitizing or validating external document content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — customs-trade-compliance