risk-management-specialist

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze data from external sources including customer complaints, clinical literature, and vigilance reports, creating a surface for indirect prompt injection. \n
  • Ingestion points: SKILL.md and referenced guides specify monitoring and updating risk files based on incoming post-market information.\n
  • Boundary markers: No explicit delimiters or instructions are provided to separate untrusted data from the agent's core instructions.\n
  • Capability inventory: The skill facilitates risk evaluation, benefit-risk analysis, and execution of local calculation scripts.\n
  • Sanitization: No sanitization or validation logic for the external data is described.\n- [COMMAND_EXECUTION]: The skill references and utilizes a local Python utility, risk_matrix_calculator.py, for performing ISO 14971 5x5 matrix and FMEA RPN calculations. This script is presented as an internal tool within the skill's script directory for automated risk assessment support.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:05 PM
Security Audit — agent-trust-hub — risk-management-specialist