ai-governance

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a comprehensive methodology for AI governance and contains no executable code other than two benign Python scripts for maturity scoring and risk tiering.
  • [COMMAND_EXECUTION]: The provided scripts governance-maturity.py and use-case-risk-tier.py use standard Python libraries to process JSON inputs. The AST findings regarding subprocess.run() in the test files (test_use_case_risk_tier.py, test_governance_maturity.py) are benign, as they are used solely to test the CLI behavior of the respective scripts by invoking the Python interpreter on local files. There is no user-controlled command injection vulnerability.
  • [DATA_EXPOSURE]: The skill provides templates (e.g., model-risk-assessment.md, third-party-due-diligence.md) that prompt for sensitive information such as data sensitivity and vendor details. These are intended for internal organizational use and do not involve any network calls or exfiltration mechanisms. The scripts are read-only and do not transmit data.
  • [PROMPT_INJECTION]: No prompt injection patterns were detected. The instructions focus on guiding the agent through governance reviews and mapping regulations to controls without attempting to bypass safety filters or override system behavior.
  • [EXTERNAL_DOWNLOADS]: The skill refers to numerous official regulatory and standards-body websites (FDA, EMA, NIST, ISO) as primary sources. All identified URLs point to trusted intergovernmental and governmental organizations, and the skill does not perform any automated downloads from these sites.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 06:35 PM
Security Audit — agent-trust-hub — ai-governance