regulatory-analysis
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data (compliance documents and process descriptions), creating a surface for indirect prompt injection.
- Ingestion points: External documents and process descriptions provided for analysis (SKILL.md).
- Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands within the analyzed documents.
- Capability inventory: The skill is restricted to the 'search-regulations' tool.
- Sanitization: No explicit sanitization or validation of the input content is defined.
- [NO_CODE]: The skill consists entirely of natural language instructions and metadata. No Python scripts, JavaScript files, or other executable binaries are included in the package.
Audit Metadata