isms-audit-expert
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external information security management system (ISMS) documentation, which represents an attack surface for instructions hidden within processed data.
- Ingestion points: Security policies, procedures, and control evidence as described in the audit execution sections of
SKILL.md. - Boundary markers: The skill does not provide specific instructions or markers to isolate untrusted content from the agent's core instructions.
- Capability inventory: The skill documentation references automated scripts for control testing (
security-control-tester.py) and compliance reporting (compliance-reporting.py), although these files are not present in the skill package. - Sanitization: There are no visible validation or sanitization steps for the ingested audit data.
- [NO_CODE]: The provided skill is primarily documentation; multiple scripts and reference guides mentioned in
SKILL.md(e.g.,isms-audit-scheduler.py,security-control-tester.py,iso27001-audit-methodology.md) were missing from the analyzed files.
Audit Metadata