data-act-vertragsklauseln

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of contract drafts ("Vertragsentwurf") and clause sets to perform legal assessments. This content is processed by sub-agents (researcher, drafter, reviewer) and used to generate command-line arguments for a local legal calculation tool (scripts.legal_calc.cli).
  • Ingestion points: User-provided contract drafts and role definitions specified in SKILL.md under the "Eingaben" section.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious instructions embedded within the contract text.
  • Capability inventory: The skill invokes a local Python script (scripts.legal_calc.cli) to calculate dates, periods, and limitation periods based on information extracted from the input text.
  • Sanitization: There is no evidence of input validation or sanitization to ensure that the content of the contracts does not attempt to manipulate the agent's behavior or the parameters passed to the calculation script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:21 AM
Security Audit — agent-trust-hub — data-act-vertragsklauseln