bfsg-anwendungsbereich
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses an internal project script to perform legal deadline calculations.\n
- Evidence: Shell commands like
python -m scripts.legal_calc.cliare documented inSKILL.mdto compute the 15-year limit for self-service terminals.\n - Context: The script resides at
../../../scripts/legal_calc/and is a local dependency.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted product descriptions and contract details, which could theoretically contain instructions intended to influence the agent.\n - Ingestion points: Inputs such as 'Produkt- oder Dienstleistungsbeschreibung' and 'Bestehende Dienstleistungsverträge'.\n
- Boundary markers: None are defined to separate user data from agent instructions.\n
- Capability inventory: The skill has the ability to invoke local Python scripts and interact with multiple sub-agents.\n
- Sanitization: No specific input sanitization or validation logic is implemented.
Audit Metadata