bfsg-dienstleistung-ecommerce

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input data, including technical reports and consumer complaints. This creates a theoretical surface where malicious instructions embedded in those documents could attempt to influence the agent's behavior.\n
  • Ingestion points: Inputs defined in SKILL.md such as 'Technischer Stand', 'Vorhandene Barrierefreiheitsinformationen', and 'Vorliegender Verbraucher- oder Verbandsantrag'.\n
  • Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to ignore potentially malicious embedded content in the ingested data.\n
  • Capability inventory: The skill utilizes a local Python script (scripts.legal_calc.cli) via shell execution to perform date calculations.\n
  • Sanitization: No explicit sanitization or escaping of external content is mentioned before it is processed or used in logic.\n- [DYNAMIC_EXECUTION]: The skill involves the execution of a local CLI tool (scripts.legal_calc.cli) using python -m. This is used to calculate legal deadlines based on input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:21 AM
Security Audit — agent-trust-hub — bfsg-dienstleistung-ecommerce