quality-management-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data into its quality management logic.\n
  • Ingestion points: Data ingestion happens in references/EXAMPLES.md via the nc_data and finding_data dictionaries which store user-provided descriptions of quality issues.\n
  • Boundary markers: There are no explicit instructions or delimiters to prevent the agent from following instructions hidden within audit finding descriptions or nonconformance reports.\n
  • Capability inventory: The skill is granted Write and WebSearch permissions in SKILL.md, providing a potential sink for malicious instructions found in processed data.\n
  • Sanitization: The provided implementation logic does not include sanitization or validation of input strings before they are stored or processed by the quality management system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — quality-management-expert