rbac-design

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze external role definitions, permission policies, and authorization configurations, which presents a potential surface for indirect prompt injection attacks.
  • Ingestion points: The skill ingests target files or directories provided as arguments to evaluate their security design (SKILL.md).
  • Boundary markers: Present. The skill includes specific sections ('Injection Hardening' and 'Prompt Injection Safety Notice') that explicitly instruct the agent to treat input as untrusted and disregard any embedded directives such as 'ignore previous instructions'.
  • Capability inventory: The skill is restricted to read-only operations using 'Read', 'Grep', and 'Glob' tools. It does not have access to tools for file writing, network communication, or code execution.
  • Sanitization: The skill relies on natural language instructions to the LLM to maintain a security boundary when processing untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:49 PM
Security Audit — agent-trust-hub — rbac-design