sumsub-analyze-regulation

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external regulatory documents such as PDFs or text-based legal acts provided by the user.
  • Ingestion points: Regulatory documents (PDFs, legal acts) provided by the user for analysis.
  • Boundary markers: The skill implements a mandatory validation step (Step 3: Validate understanding first) where the agent must present its extracted requirements to the user and receive explicit confirmation before proceeding to generate the full plan.
  • Capability inventory: The skill is restricted to the Read tool and produces only text-based planning descriptions. It is explicitly prohibited from generating JSON payloads or making API calls.
  • Sanitization: The skill relies on human review of the intermediate "My Understanding" block to identify and correct any misinterpretations or malicious instructions embedded in the source documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:33 PM
Security Audit — agent-trust-hub — sumsub-analyze-regulation