simready-foundation-conform-fet-100-isaac

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions.
  • Ingestion points: The workflow involves reading external profile TOML files, validation reports, and user-provided requests to identify conformance failures (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or guardrails to distinguish between data and instructions when reading these external files.
  • Capability inventory: The agent is authorized to modify files (staged or in-place) and execute validation commands or profile gates to verify repairs (SKILL.md).
  • Sanitization: There are no explicit instructions for sanitizing or escaping the content retrieved from validation reports or profiles before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-conform-fet-100-isaac