betriebskostenabrechnung
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local Python module
scripts.legal_calc.clilocated within the project's relative path to perform arithmetic for legal deadlines. This constitutes controlled execution of local tooling intended for the skill's primary function. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process the verbatim text of utility bills and rental agreements. This creates an attack surface where malicious instructions could be embedded in the input data (e.g., within the bill's text).
- Ingestion points: Raw text input of utility bills and rental agreements in
SKILL.md. - Boundary markers: None explicitly defined in the prompt instructions to separate user data from system instructions.
- Capability inventory: Uses
scripts.legal_calc.clivia subprocess for date calculations. - Sanitization: No specific sanitization or filtering of input text is documented.
Audit Metadata