keel-comply
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's instructions and structure are consistent with its stated purpose as a compliance auditing assistant. No malicious prompt injections, hidden commands, or persistence mechanisms were found.
- [COMMAND_EXECUTION]: The skill requests access to the
Bashtool in its frontmatter configuration. This capability is used to support the operations engineering tasks described in the skill, such as inspecting configurations or system states for compliance evidence. - [DATA_EXPOSURE]: By design, the skill prompts the user for sensitive information related to security controls, including IAM policies, database encryption settings, and incident response plans. This data collection is necessary for performing a gap analysis and is handled within the context of the agent's interaction with the user.
- [EXTERNAL_DOWNLOADS]: The skill allows the use of
WebFetchandWebSearchto research compliance requirements and frameworks. No specific malicious URLs or unauthorized remote code execution patterns were identified.
Audit Metadata