ciso-advisor

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access behaviors were detected across the skill's instructions, references, or scripts.- [COMMAND_EXECUTION]: The skill includes Python scripts (risk_quantifier.py, compliance_tracker.py) designed for local risk analysis and compliance mapping. These scripts are safe, utilizing only standard Python libraries and performing no dangerous operations such as network requests or shell command execution.- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by instructing the agent to ingest data from company-context.md. While this is an ingestion point for potentially untrusted data, the skill's capabilities are limited to advisory reporting and role invocation, and no malicious overrides were identified.
  • Ingestion points: company-context.md (referenced in SKILL.md)
  • Boundary markers: None present in the provided instructions.
  • Capability inventory: Internal role invocation ([INVOKE:role|question]) and report generation.
  • Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 08:16 AM
Security Audit — agent-trust-hub — ciso-advisor