betriebsuebergang
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves analyzing external, user-provided documents (specifically legal notification letters) to detect errors or omissions. This creates a surface for indirect prompt injection where instructions could be embedded in the text being analyzed.
- Ingestion points: The skill ingests user-supplied "Unterrichtungsschreiben" (notification letters) as part of its core logic defined in the Purpose and Flow sections.
- Boundary markers: The skill body does not define specific delimiters or instructions to ignore embedded commands within the analyzed data.
- Capability inventory: Analysis of the skill and its referenced sub-agent architecture (researcher, drafter, reviewer) shows no capabilities for network exfiltration, arbitrary command execution, or persistent file system modifications.
- Sanitization: There are no explicit filtering or sanitization steps mentioned for the input data.
- [SAFE]: All external URL references target official government legal databases (gesetze-im-internet.de), established legal repositories (dejure.org), or official judicial portals (bundesarbeitsgericht.de, curia.europa.eu). These are trusted resources for the skill's legal domain.
Audit Metadata