compliance-testing
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's instructions, configuration, and evaluation suites are consistent with its stated purpose of regulatory compliance testing. No malicious patterns, unauthorized credential access, or exfiltration attempts were detected.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze third-party source code and API responses for compliance gaps, which represents a potential surface for indirect prompt injection if the analyzed content contains malicious instructions.\n
- Ingestion points: Audited application source code and responses from tested API endpoints.\n
- Boundary markers: The skill includes guidance in SKILL.md to verify all claims and avoid trusting absolute compliance reports (e.g., "verify each claim", "100% compliant are suspicious").\n
- Capability inventory: Agent coordination via FleetManager to execute tests and generate audit-ready reports.\n
- Sanitization: The skill relies on the underlying platform's safety guardrails when processing untrusted code and data.
Audit Metadata