quality-manager-qmr

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behaviors, such as data exfiltration, credential harvesting, or unauthorized remote code execution, were detected in the instructions or reference materials.
  • [PROMPT_INJECTION]: The skill identifies a workflow for aggregating external data like customer feedback and audit reports, which is a known surface for indirect prompt injection. 1. Ingestion points: Management review input collection (e.g., complaints, feedback). 2. Boundary markers: Absent in the provided templates. 3. Capability inventory: Execution of a local management_review_tracker.py script. 4. Sanitization: No explicit sanitization or validation of external input is defined.
  • [COMMAND_EXECUTION]: The skill references a local script for tracking quality metrics, which is a standard functional component of the workflow provided by the author.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:05 PM
Security Audit — agent-trust-hub — quality-manager-qmr