soc2-gap
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to ignore any commands or overrides found within the files it analyzes. These patterns, while often associated with prompt injection, are used here as a defensive guardrail against indirect prompt injection attacks.
- [DATA_EXPOSURE]: The skill is designed to read sensitive infrastructure and security configurations for audit purposes. However, it lacks the tools necessary for network communication or data exfiltration, and no hardcoded credentials or malicious scripts were identified.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface as it ingests untrusted data from codebases and infrastructure repositories. This risk is mitigated by explicit boundary instructions to the agent to disregard embedded directives and the absence of high-risk capabilities like network access or write permissions.
Audit Metadata