saudi-arabia-grc

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements an 'Intake Gate' that requests sensitive organizational information, creating an inherent surface for indirect prompt injection where malicious data could attempt to influence advisor behavior.\n
  • Ingestion points: Step 1 in SKILL.md prompts for detailed metadata including organization type, data classification, and cloud posture.\n
  • Boundary markers: The instructions lack explicit delimiters or safety instructions to isolate and ignore potentially malicious commands embedded within the user's descriptive responses.\n
  • Capability inventory: The skill is strictly informational and reference-based; it does not request or utilize tools for file system modification, command execution, or network communication.\n
  • Sanitization: No validation or sanitization mechanisms are defined for the content processed during the intake workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 10:35 PM
Security Audit — agent-trust-hub — saudi-arabia-grc