dora-register-builder

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a low-severity attack surface for indirect prompt injection because its primary function involves the ingestion and processing of untrusted data from various external sources.
  • Ingestion points: Untrusted data enters the agent context via files such as TPRM register exports, contract repositories, and vendor-diligence packs as detailed in the skill instructions.
  • Boundary markers: The instructions do not specify the use of clear delimiters or explicit instructions to the agent to disregard potential commands embedded within the external data.
  • Capability inventory: The skill is capable of generating structured JSON data and markdown reports and relies on coordination with other skills like contract-gap-review and vendor-diligence.
  • Sanitization: The logic does not define methods for validating or sanitizing the content of ingested files before they are processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches information from official regulatory domains and well-known services, including the European Union's official legal database (eur-lex.europa.eu) and the European Banking Authority (eba.europa.eu). These are recognized as trusted sources and documented neutrally.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:14 AM
Security Audit — agent-trust-hub — dora-register-builder