soc2-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to assist with SOC 2 compliance, which involves processing data from external sources like Jira tickets and system logs. This creates a potential surface for indirect prompt injection.
- Ingestion points: Processes user compliance queries and interacts with external data sources referenced in the evidence collection script (SKILL.md).
- Boundary markers: As this is a knowledge-based skill, it does not define operational boundaries for data segregation.
- Capability inventory: The skill is configured to use tools including
Bash,Write,Edit,Read, andGrep. - Sanitization: The provided code snippets serve as educational templates and do not include production-ready input validation or sanitization logic.
Audit Metadata