vendor-due-diligence
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: A thorough analysis of the skill's instructions, reference documents, and scripts revealed no malicious patterns, obfuscation, or safety bypass attempts. The skill serves its stated purpose of providing a framework for vendor risk assessment.
- [COMMAND_EXECUTION]: The skill provides two Python utility scripts (
vendor_risk_scorer.pyandvendor_comparison.py) intended for data analysis. Technical review of these scripts confirms they strictly utilize standard Python libraries (json,sys,argparse) to process local JSON files provided by the user. They do not perform network operations, unauthorized file access, or execute arbitrary system commands. - [EXTERNAL_DOWNLOADS]: The skill does not include any external dependencies, package installation instructions, or remote script execution patterns. All logic is contained within the provided scripts and markdown files.
- [PROMPT_INJECTION]: The content within
SKILL.mdand the reference guides consists of professional assessment criteria and workflow instructions. No patterns of prompt injection, role-play bypasses, or instructions to ignore safety guidelines were detected.
Audit Metadata