Compliance Automation Engine
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted compliance evidence from a user-provided directory path.
- Ingestion points:
evidence_pathinput parameter used to scan logs, policies, and configuration files. - Boundary markers: Output is constrained by structured JSON schemas defined in the output contract and external resource files.
- Capability inventory: Performs file writing for reports and OSCAL artifacts; performs network reads from authoritative regulatory domains.
- Sanitization: Implements pattern scanning to identify and exclude secrets, API keys, and PII from generated artifacts.
- [EXTERNAL_DOWNLOADS]: The skill references and fetches configuration, schemas, and control catalogs from official government and industry repositories.
- Evidence: Links to reputable domains such as nist.gov, fedramp.gov, and the official usnistgov GitHub organization for OSCAL schema validation and control baseline data.
Audit Metadata