cra-schwachstellenmanagement

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions focus exclusively on regulatory compliance and procedural guidance. No executable code, shell commands, or suspicious scripts are included in the skill body.
  • [EXTERNAL_DOWNLOADS]: The skill references official legislative documents from trusted institutional domains, including the European Union's Eur-Lex and the German Federal Office for Information Security (BSI). These references are documented neutrally and serve as authoritative sources for the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting external vulnerability reports (SKILL.md, 'Eingaben'). While this represents an attack surface for indirect prompt injection, the skill mandates a structured triage and verification process ('Triage und Bewertung'), and does not possess capabilities like file system writes or arbitrary network execution that would facilitate a compromise.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:20 AM
Security Audit — agent-trust-hub — cra-schwachstellenmanagement