nzism

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted user-supplied data (such as system descriptions and current control status) to generate compliance guidance and documentation.
  • Ingestion points: User-provided system context and current security posture processed in SKILL.md (Workflow 1: Gap Analysis).
  • Boundary markers: The instructions lack explicit delimiters or warnings (e.g., 'ignore embedded instructions') to prevent the agent from obeying malicious instructions embedded within the user data.
  • Capability inventory: The skill is restricted to textual analysis and guidance; it does not exhibit capabilities for file system modification, network exfiltration, or subprocess execution, which significantly mitigates the impact of potential injection.
  • Sanitization: No specific mechanisms for sanitizing or validating user-provided content are defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — nzism