isms-audit-expert

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external information security management system (ISMS) documentation, which represents an attack surface for instructions hidden within processed data.
  • Ingestion points: Security policies, procedures, and control evidence as described in the audit execution sections of SKILL.md.
  • Boundary markers: The skill does not provide specific instructions or markers to isolate untrusted content from the agent's core instructions.
  • Capability inventory: The skill documentation references automated scripts for control testing (security-control-tester.py) and compliance reporting (compliance-reporting.py), although these files are not present in the skill package.
  • Sanitization: There are no visible validation or sanitization steps for the ingested audit data.
  • [NO_CODE]: The provided skill is primarily documentation; multiple scripts and reference guides mentioned in SKILL.md (e.g., isms-audit-scheduler.py, security-control-tester.py, iso27001-audit-methodology.md) were missing from the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 12:07 AM
Security Audit — agent-trust-hub — isms-audit-expert