simready-foundation-conform-fet-011-standard
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external validation reports and requirement documentation to guide repair tasks. Ingestion points: SKILL.md workflow steps indicate the ingestion of profile TOML files, validation reports, and requirement documentation. Boundary markers: No specific delimiters are defined to separate external report content from the agent's core instructions. Capability inventory: The skill utilizes file-writing capabilities to repair assets and command execution to run validation gates. Sanitization: No explicit sanitization of external data is specified in the instructions.
- [COMMAND_EXECUTION]: The workflow requires the execution of validation commands to verify the success of asset repairs. Evidence: SKILL.md instructions (Workflow step 6) and the 'Report Fields' table explicitly reference running validation gates and commands. Context: These actions are restricted to the primary purpose of the skill within a technical development environment and do not involve unauthorized shell access.
Audit Metadata