llm-risk-assess
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate security assessment methodologies based on industry-standard OWASP guidelines. No malicious patterns, obfuscation, or unauthorized access attempts were detected in the provided markdown file.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a security auditing workflow that ingests untrusted data from external applications, including architecture documentation, data flows, and test logs (SKILL.md).
- Ingestion points: Steps 1 (Architecture & Threat Modeling) and 4 (Red Team Testing) involve processing data from external sources.
- Boundary markers: No explicit delimiters or instructions to ignore embedded prompts are provided in the workflow.
- Capability inventory: The skill allows the use of Bash, WebFetch, Read, and Agent tools, which could be leveraged if the agent follows instructions hidden within analyzed documents.
- Sanitization: The instructions do not specify any sanitization, validation, or escaping of the external content processed during the audit.
Audit Metadata