simready-foundation-conform-fet-028-isaac
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data sources, such as validation reports, profile TOML files, and user requests, to drive automated file repairs.
- Ingestion points: Profile TOML, validation reports, and feature manifests (JSON/Markdown) located in
nv_core/sr_specs/docs/features/. - Boundary markers: The instructions do not define specific delimiters to isolate external data from the agent's instruction set.
- Capability inventory: The skill performs file system modifications ('repair') to address conformance failures.
- Sanitization: There are no documented procedures for sanitizing or validating the content of reports or user requests before processing.
- [COMMAND_EXECUTION]: The skill instructs the agent to run validation gates and profile gates to verify conformance repairs.
- Context: This is a standard part of the SimReady development workflow and involves running project-specific tooling as specified in the feature manifest.
Audit Metadata