regulatory-change-impact

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed entirely of markdown instructions and templates for performing business impact assessments related to regulatory changes. it does not include any scripts, executable code, or configurations that would enable network communication or file system modifications.
  • [DATA_EXPOSURE]: While the skill instructions prompt the agent to process sensitive organizational data such as revenue and product portfolios, there are no tools or code elements defined that would allow for the exfiltration of this data.
  • [NO_CODE]: No python packages, node.js packages, or remote code patterns were detected within the skill.
  • [PROMPT_INJECTION]: The skill is designed to ingest external data (regulation details) which presents an indirect prompt injection surface. however, because the skill lacks any 'allowed-tools' or executable capabilities (e.g., file writing, shell access, or network calls), there is no risk of a malicious payload within the ingested text causing harm. the skill lacks explicit boundary markers or sanitization for this external input.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 12:01 AM
Security Audit — agent-trust-hub — regulatory-change-impact