cra-produktanforderungen
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external documentation, architecture descriptions, and security assessments provided by the user. This creates a surface for indirect prompt injection where malicious instructions could be embedded within the analyzed product data to manipulate the agent's compliance report or recommendations.
- Ingestion points: The skill accepts various user-provided inputs including product context, technical architecture, inventories, and existing security documentation as listed in the 'Eingaben' section of SKILL.md.
- Boundary markers: The instructions do not specify any delimiters or safety prompts to isolate user-provided data from the agent's core instructions.
- Capability inventory: The skill description focuses on complex reasoning and reporting; no explicit tool invocation or shell command execution is listed in the frontmatter or body.
- Sanitization: No input validation or sanitization mechanisms are defined in the skill logic.
- [SAFE]: The skill incorporates references to official European Union legal texts and government agency websites, such as eur-lex.europa.eu, digital-strategy.ec.europa.eu, and bsi.bund.de. These resources are well-known, authoritative sources for regulatory information and are used neutrally to provide the necessary legal framework for the analysis.
Audit Metadata