information-security-manager-iso27001

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it ingests and processes untrusted data from external sources.
  • Ingestion points: Data enters the agent context through scripts/risk_assessment.py (via the --assets parameter) and scripts/compliance_checker.py (via the --controls-file parameter).
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from being influenced by natural language instructions that might be embedded within the asset names or control statuses in the CSV files.
  • Capability inventory: The skill allows for local command execution (running Python scripts) and file system access (reading CSVs and writing reports).
  • Sanitization: The tool lacks specific sanitization routines to identify or neutralize potential prompt injection payloads within the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 08:17 AM
Security Audit — agent-trust-hub — information-security-manager-iso27001