simready-foundation-conform-fet-030-standard
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources, including profile TOML files, validation reports, and asset package roots, to identify and repair conformance failures. This data ingestion creates a surface for indirect prompt injection where malicious instructions could be embedded in the processed files.\n
- Ingestion points: Data enters the agent's context from profile TOML files, validation reports, and asset package roots as part of the initial inspection and repair workflow in SKILL.md.\n
- Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore embedded commands within the analyzed external data.\n
- Capability inventory: The skill is capable of performing file system writes (for staged or in-place repairs) and executing validation gates or commands to verify the asset's state (SKILL.md).\n
- Sanitization: The workflow does not specify any sanitization, filtering, or schema validation for the contents of the external reports or asset files before they are processed by the agent.
Audit Metadata