zero-trust-assessment

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a standard architectural assessment guide focused on NIST SP 800-207 and CISA ZTMM frameworks. It does not contain any executable scripts, remote downloads, or credential-gathering mechanisms.
  • [PROMPT_INJECTION]: The static detector flagged 'ignore previous instructions' patterns; however, these are used defensively within the skill's 'Injection Hardening' and 'Prompt Injection Safety Notice' sections. These sections explicitly instruct the agent to ignore and report any such instructions found in the untrusted architecture data it analyzes, which is a security best practice rather than a malicious attempt to subvert the system.
  • [COMMAND_EXECUTION]: While the skill's frontmatter allows tools like Read, Grep, and Glob, these are used solely for the purpose of analyzing existing documentation and configuration files as specified in the skill's assessment process. The skill explicitly forbids executing configuration changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of processing untrusted architecture and configuration data (Category 8 surface). It mitigates this risk through a dedicated 'Injection Hardening' section that establishes a security boundary and provides clear instructions on how to handle adversarial content embedded in diagrams or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:48 PM
Security Audit — agent-trust-hub — zero-trust-assessment