nzism
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted user-supplied data (such as system descriptions and current control status) to generate compliance guidance and documentation.
- Ingestion points: User-provided system context and current security posture processed in
SKILL.md(Workflow 1: Gap Analysis). - Boundary markers: The instructions lack explicit delimiters or warnings (e.g., 'ignore embedded instructions') to prevent the agent from obeying malicious instructions embedded within the user data.
- Capability inventory: The skill is restricted to textual analysis and guidance; it does not exhibit capabilities for file system modification, network exfiltration, or subprocess execution, which significantly mitigates the impact of potential injection.
- Sanitization: No specific mechanisms for sanitizing or validating user-provided content are defined in the instructions.
Audit Metadata