compliance-checker

Warn

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The skill's primary function involves identifying and accessing highly sensitive file paths and contents, including environment variables (.env), private keys (.pem, .key), and database credentials (references/scan-patterns.md). While intended for compliance auditing, this grants the agent access to critical system secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes untrusted data from external codebases and infrastructure configurations (Phase 2). It lacks explicit sanitization or boundary markers (such as XML delimiters) when interpolating evidence snippets into the report generation process (references/output-template.md). Ingestion points: codebase and documentation scanning. Boundary markers: Absent. Capability inventory: Bash, Write, Read, Grep, Glob. Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute search patterns and automated scanning for compliance evidence across all project file types (references/scan-patterns.md).
  • [EXTERNAL_DOWNLOADS]: The skill references official regulatory guidance and framework documentation from well-known government and industry services, including eur-lex.europa.eu, hhs.gov, and pcisecuritystandards.org.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — compliance-checker