nist-csf-assessment
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No security risks were identified. The skill is entirely composed of instructional content and framework documentation.
- [PROMPT_INJECTION]: While the skill contains phrases typically associated with prompt injection (e.g., 'disregard previous instructions'), they are used exclusively for defensive purposes. The 'Prompt Injection Safety Notice' correctly instructs the agent to treat processed documents as untrusted data and to ignore any embedded directives aimed at overriding the assessment process.
- [SAFE]: The skill requests access to read-only tools (Read, Grep, Glob) to facilitate documentation review. There are no patterns suggesting data exfiltration, credential harvesting, or unauthorized system changes.
Audit Metadata