preparing-compliance-documentation
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides informational guidance and read-only diagnostic commands for auditing cluster security and compliance posture.\n- [COMMAND_EXECUTION]: Includes standard administrative SQL queries and
ccloudCLI commands used for auditing cluster settings, network allowlists, and configuration info. All commands are diagnostic in nature.\n- [DATA_EXPOSURE]: Instructions focus on viewing security configurations (e.g., password policies, admin counts, encryption status). No commands for exfiltrating sensitive data to external domains were found.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes output from local CLI tools and database queries to assess compliance status. While it lacks explicit boundary markers for the data it processes, the potential for exploitation is minimal given the diagnostic scope and lack of network-write capabilities.
Audit Metadata