commerce-message-compliance-kr
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user-provided message drafts as part of its core functionality.
- Ingestion points: The workflow takes a "message draft" as a required input slot in
SKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or specific instructions to isolate the user-provided draft from the compliance logic.
- Capability inventory: No exploitable capabilities (e.g., shell access, file system manipulation, or network tools) were identified within the skill's defined operations.
- Sanitization: The skill does not explicitly mention sanitization or validation of the input draft content.
- [SAFE]: The skill consists entirely of markdown instructions and rules. No obfuscation, base64 encoding, remote code downloads, or persistence mechanisms were found. All mentioned logic pertains to legal compliance checks within the Korean jurisdiction.
Audit Metadata