simready-foundation-conform-fet-028-standard
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from JSON manifests and Markdown documentation to guide the agent's repair actions, which could be exploited to provide malicious instructions via document content.
- Ingestion points: The workflow requires loading local specification files located at
nv_core/sr_specs/docs/features/FET_028_STANDARD-0.1.0.jsonandnv_core/sr_specs/docs/features/FET_028_STANDARD.md, as well as linked requirement documents. - Boundary markers: No explicit delimiters or instructions to disregard potential commands within the loaded specifications are provided to the agent.
- Capability inventory: The agent is authorized to modify asset files and package definitions according to the requirements identified in the ingested data.
- Sanitization: The instructions do not define any validation, filtering, or sanitization steps for the data retrieved from the specification files.
Audit Metadata