sota-security-compliance
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill introduces an attack surface for indirect prompt injection by instructing the agent on how to triage and process untrusted external data from vulnerability reports.\n
- Ingestion points: The "Triaging a report someone else sent you" section in
rules/04-eu-cyber-resilience-act.mddefines a workflow for ingesting data from Coordinated Vulnerability Disclosure (CVD) intakes and security portals.\n - Boundary markers: The skill includes procedural boundary markers in the form of a triage rubric, advising the agent to "Reproduce before you rate" and "Check that the cited code exists" to detect machine-generated or deceptive reports.\n
- Capability inventory: The skill is intended for use in contexts involving code review, file system access, and integration with other development tools (as referenced by the
sota-*library), which could be exploited if malicious data is processed without sufficient caution.\n - Sanitization: The instructions focus on logical validation and reproducibility rather than technical sanitization or filtering of the input text.
Audit Metadata