grc-compliance

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for ingesting and processing data from external ServiceNow tables (e.g., sn_compliance_policy, sn_risk_risk). This creates a vulnerability surface for indirect prompt injection if GRC records contain malicious instructions.
  • Ingestion points: Data is retrieved from various sn_* tables via snow_query_table as shown in the Example Workflow section of SKILL.md.
  • Boundary markers: No explicit delimiters or instruction-ignore warnings are present in the script templates.
  • Capability inventory: The skill utilizes snow_execute_script for server-side operations and snow_query_table for data access.
  • Sanitization: Input data (like testData or findingData) is interpolated into script blocks without explicit sanitization or validation logic shown in the examples.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of server-side JavaScript (ES5) within a ServiceNow instance via the snow_execute_script tool. These operations are restricted to GRC management tasks as per the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:26 PM
Security Audit — agent-trust-hub — grc-compliance