soc2-gap

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill contains no executable code, binaries, or scripts. It is composed entirely of Markdown documentation and instructions. No hardcoded credentials, unauthorized network operations, or obfuscation techniques were detected.
  • [PROMPT_INJECTION]: The skill is designed to process untrusted external data, including codebase files, infrastructure configurations, and policy documents (Ingestion points: SKILL.md). It includes explicit instructions for the agent to treat any commands or instruction-overrides found within these documents as data to be analyzed rather than directives to be followed (Boundary markers: Present). The skill's functionality is limited to read-only operations (Capability inventory: Read, Grep, Glob), and while no specific sanitization is mentioned, the lack of file-writing or network-access capabilities significantly limits the potential for exploitation via indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:49 PM
Security Audit — agent-trust-hub — soc2-gap