ai-on-saas-risk-and-responsible-ai

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill provides structured guidance and templates for AI risk management and governance documentation without introducing security risks.\n- [NO_CODE]: The skill consists entirely of Markdown instructions, tables, and reference links to local documents. It does not contain any executable scripts, shell commands, or automation code.\n- [SAFE]: The acknowledgement section mentions the author's website and contact information. This is attribution for the community-shared resource and does not involve automated network operations, exfiltration patterns, or suspicious destinations.\n- [PROMPT_INJECTION]: The skill defines a workflow for processing external inputs such as tender and discovery documents, creating a surface for indirect prompt injection. 1. Ingestion points: Reads tender, discovery, architecture, and security evidence (SKILL.md). 2. Boundary markers: Explicit 'Stop condition' in workflow and 'Capability and Permission Boundaries' section provided. 3. Capability inventory: Limited to drafting text artefacts; no network, shell, or file-write capabilities are defined. 4. Sanitization: None explicitly defined. The risk is assessed as SAFE due to the lack of powerful tools or autonomous capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:11 AM
Security Audit — agent-trust-hub — ai-on-saas-risk-and-responsible-ai