soc2-gap
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill contains no executable code, binaries, or scripts. It is composed entirely of Markdown documentation and instructions. No hardcoded credentials, unauthorized network operations, or obfuscation techniques were detected.
- [PROMPT_INJECTION]: The skill is designed to process untrusted external data, including codebase files, infrastructure configurations, and policy documents (Ingestion points: SKILL.md). It includes explicit instructions for the agent to treat any commands or instruction-overrides found within these documents as data to be analyzed rather than directives to be followed (Boundary markers: Present). The skill's functionality is limited to read-only operations (Capability inventory: Read, Grep, Glob), and while no specific sanitization is mentioned, the lack of file-writing or network-access capabilities significantly limits the potential for exploitation via indirect prompt injection.
Audit Metadata