Compliance Automation Engine

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted compliance evidence from a user-provided directory path.
  • Ingestion points: evidence_path input parameter used to scan logs, policies, and configuration files.
  • Boundary markers: Output is constrained by structured JSON schemas defined in the output contract and external resource files.
  • Capability inventory: Performs file writing for reports and OSCAL artifacts; performs network reads from authoritative regulatory domains.
  • Sanitization: Implements pattern scanning to identify and exclude secrets, API keys, and PII from generated artifacts.
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches configuration, schemas, and control catalogs from official government and industry repositories.
  • Evidence: Links to reputable domains such as nist.gov, fedramp.gov, and the official usnistgov GitHub organization for OSCAL schema validation and control baseline data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:57 PM
Security Audit — agent-trust-hub — Compliance Automation Engine