ai-product-operating-model
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The provided Python scripts (contract_validator.py and risk_tier_classifier.py) are focused on data processing tasks—specifically validating JSON schemas and classifying risk based on keywords. They use standard libraries for file I/O and do not perform any unsafe system calls or process execution.
- [INDIRECT_PROMPT_INJECTION]: The risk classification script parses user-provided text or JSON files. However, its operation is restricted to basic string matching against predefined risk signals and does not interpret or execute instructions found within the input content.
- [EXTERNAL_DOWNLOADS]: The skill references several external documentation sources and regulatory websites (e.g., NIST, EU AI Act official pages, Anthropic/OpenAI documentation). All referenced domains are well-known, official, and relevant to the skill's purpose, presenting no security risk.
Audit Metadata