regulatory-analysis

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data (compliance documents and process descriptions), creating a surface for indirect prompt injection.
  • Ingestion points: External documents and process descriptions provided for analysis (SKILL.md).
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands within the analyzed documents.
  • Capability inventory: The skill is restricted to the 'search-regulations' tool.
  • Sanitization: No explicit sanitization or validation of the input content is defined.
  • [NO_CODE]: The skill consists entirely of natural language instructions and metadata. No Python scripts, JavaScript files, or other executable binaries are included in the package.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 09:52 AM
Security Audit — agent-trust-hub — regulatory-analysis