cloud-anbieterwechsel

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external contract text and user-provided parameters to verify compliance with the EU Data Act. This process involves a data ingestion surface that could potentially contain malicious instructions embedded within the contract text to influence the agent's behavior.\n
  • Ingestion points: Legal contract clauses, exit strategy descriptions, and data inventory metadata provided by the user.\n
  • Boundary markers: The skill does not explicitly utilize delimiters or "ignore instructions" directives for the processed contract data.\n
  • Capability inventory: The agent has the ability to execute a local Python script for date calculations and interact with sub-agents for legal research and drafting.\n
  • Sanitization: No specific text sanitization or filtering mechanism for the ingested contract text is identified.\n- [COMMAND_EXECUTION]: The skill documentation includes instructions for running a local CLI tool (scripts.legal_calc.cli) to perform deterministic date calculations for legal deadlines. While this involves command execution, it targets a local repository script with defined parameters for calculation purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:21 AM
Security Audit — agent-trust-hub — cloud-anbieterwechsel