pci-compliance
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists entirely of documentation and instructional Markdown files. There are no scripts, binaries, or configuration files that execute commands or perform network operations.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to review external data sources like application logs, queues, and backups for evidence. * Ingestion points:
SKILL.md(logs, telemetry, support exports),implementation-playbook.md(forms, logs, traces, queues, backups). * Boundary markers: Absent. * Capability inventory: None (no tools or scripts provided). * Sanitization: Absent (mentions redaction of account data, but not for prompt injection). The risk is assessed as safe because the skill does not possess any capabilities that could be exploited by malicious data in the ingested sources.
Audit Metadata