pci-compliance

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill provides structured guidance on PCI DSS compliance. Analysis of the core logic and reference files found no evidence of malicious intent or hidden capabilities.- [NO_CODE]: The skill is composed entirely of Markdown documentation and instructions. There are no scripts, binaries, or configuration files that execute commands on the host system.- [PROMPT_INJECTION]: Instructions are focused on setting a professional persona as a compliance consultant. No attempts to override safety filters, bypass restrictions, or extract system prompts were detected.- [DATA_EXFILTRATION]: While the skill discusses sensitive payment data (PAN, SAD) in a compliance context, it contains no mechanisms to collect, store, or transmit data to external servers. No hardcoded credentials or sensitive file path access patterns were found.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data (e.g., descriptions of IT environments) to perform gap assessments. However, since the skill has no capabilities to write files, execute code, or access the network, the surface for exploitation is minimal and presents no actionable risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — pci-compliance