sota-security-compliance

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill introduces an attack surface for indirect prompt injection by instructing the agent on how to triage and process untrusted external data from vulnerability reports.\n
  • Ingestion points: The "Triaging a report someone else sent you" section in rules/04-eu-cyber-resilience-act.md defines a workflow for ingesting data from Coordinated Vulnerability Disclosure (CVD) intakes and security portals.\n
  • Boundary markers: The skill includes procedural boundary markers in the form of a triage rubric, advising the agent to "Reproduce before you rate" and "Check that the cited code exists" to detect machine-generated or deceptive reports.\n
  • Capability inventory: The skill is intended for use in contexts involving code review, file system access, and integration with other development tools (as referenced by the sota-* library), which could be exploited if malicious data is processed without sufficient caution.\n
  • Sanitization: The instructions focus on logical validation and reproducibility rather than technical sanitization or filtering of the input text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 12:02 AM
Security Audit — agent-trust-hub — sota-security-compliance