iso-13485-certification

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a local Python script (scripts/gap_analyzer.py) to automate the analysis of documentation within a user-defined directory to identify compliance gaps.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it reads and processes data from untrusted files provided by the user.\n
  • Ingestion points: The script scripts/gap_analyzer.py ingests data from a directory of documents specified by the user.\n
  • Boundary markers: The report generated by the analysis script does not employ delimiters or ignore-instructions to isolate untrusted data from the agent's context.\n
  • Capability inventory: The skill allows for the execution of Python scripts and provides the agent with access to the local file system.\n
  • Sanitization: Input from the scanned documentation is read as raw text and checked against keyword lists without any sanitization or validation to prevent embedded instructions from influencing the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 08:22 AM
Security Audit — agent-trust-hub — iso-13485-certification