ksef-nextjs
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a comprehensive documentation suite for a sovereign government API. It utilizes native Node.js crypto modules for sensitive operations (AES-256-CBC, RSA-OAEP) and correctly handles credentials via environment variables.
- [EXTERNAL_DOWNLOADS]: The reference materials guide users toward official Ministry of Finance repositories (e.g., github.com/CIRFMF) for bootstrap tools and C# client references, which is an expected and safe practice for this integration.
- [PROMPT_INJECTION]: The skill includes specific instructions for the agent to treat incoming invoice XML as untrusted third-party content, advising against its execution or interpolation in sensitive contexts to prevent data-driven attacks.
Audit Metadata