ksef-nextjs

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a comprehensive documentation suite for a sovereign government API. It utilizes native Node.js crypto modules for sensitive operations (AES-256-CBC, RSA-OAEP) and correctly handles credentials via environment variables.
  • [EXTERNAL_DOWNLOADS]: The reference materials guide users toward official Ministry of Finance repositories (e.g., github.com/CIRFMF) for bootstrap tools and C# client references, which is an expected and safe practice for this integration.
  • [PROMPT_INJECTION]: The skill includes specific instructions for the agent to treat incoming invoice XML as untrusted third-party content, advising against its execution or interpolation in sensitive contexts to prevent data-driven attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 09:07 PM
Security Audit — agent-trust-hub — ksef-nextjs