lq-governance-playbook-benchmark

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of natural language instructions and markdown configuration. It does not include any scripts, executables, or external dependencies, significantly reducing the technical attack surface.
  • [SAFE]: The skill's data processing activities are confined to the user's active Office session (Word, Excel, PowerPoint). Access to the 'Target document' and 'LQ Governance Playbook' is functional and expected for a benchmarking tool, with no evidence of external network operations or data exfiltration.
  • [SAFE]: Analysis of the Indirect Prompt Injection attack surface:
  • Ingestion points: Processes user-provided Word documents and uploaded 'LQ Governance Playbook' files (SKILL.md).
  • Boundary markers: Implements 'Confidence Bands' (H/M/L) and a mandatory 'Halt rule' for low-confidence or ambiguous content, preventing automated processing of potentially malicious or confusing inputs.
  • Capability inventory: Limited to internal Office application tasks, such as creating tracked changes in Word, logging to Excel, and adding slides to PowerPoint (SKILL.md).
  • Sanitization: Employs a 'Delegation Threshold' policy where all agent output is explicitly designated as a 'draft for legal counsel review,' ensuring that a human expert validates all findings and amendments before they are accepted.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 08:53 AM
Security Audit — agent-trust-hub — lq-governance-playbook-benchmark