grc-compliance
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for ingesting and processing data from external ServiceNow tables (e.g.,
sn_compliance_policy,sn_risk_risk). This creates a vulnerability surface for indirect prompt injection if GRC records contain malicious instructions. - Ingestion points: Data is retrieved from various
sn_*tables viasnow_query_tableas shown in theExample Workflowsection ofSKILL.md. - Boundary markers: No explicit delimiters or instruction-ignore warnings are present in the script templates.
- Capability inventory: The skill utilizes
snow_execute_scriptfor server-side operations andsnow_query_tablefor data access. - Sanitization: Input data (like
testDataorfindingData) is interpolated into script blocks without explicit sanitization or validation logic shown in the examples. - [COMMAND_EXECUTION]: The skill facilitates the execution of server-side JavaScript (ES5) within a ServiceNow instance via the
snow_execute_scripttool. These operations are restricted to GRC management tasks as per the skill's stated purpose.
Audit Metadata