cra-produktanforderungen

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external documentation, architecture descriptions, and security assessments provided by the user. This creates a surface for indirect prompt injection where malicious instructions could be embedded within the analyzed product data to manipulate the agent's compliance report or recommendations.
  • Ingestion points: The skill accepts various user-provided inputs including product context, technical architecture, inventories, and existing security documentation as listed in the 'Eingaben' section of SKILL.md.
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to isolate user-provided data from the agent's core instructions.
  • Capability inventory: The skill description focuses on complex reasoning and reporting; no explicit tool invocation or shell command execution is listed in the frontmatter or body.
  • Sanitization: No input validation or sanitization mechanisms are defined in the skill logic.
  • [SAFE]: The skill incorporates references to official European Union legal texts and government agency websites, such as eur-lex.europa.eu, digital-strategy.ec.europa.eu, and bsi.bund.de. These resources are well-known, authoritative sources for regulatory information and are used neutrally to provide the necessary legal framework for the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:20 AM
Security Audit — agent-trust-hub — cra-produktanforderungen