dsa-notice-action

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of untrusted data in the form of legal 'Notices', creating a surface for indirect prompt injection attacks.
  • Ingestion points: Untrusted content enters the agent context via the 'Inhalt und Form der eingegangenen Meldung' and 'Behauptete Rechtswidrigkeit' fields as specified in SKILL.md.
  • Boundary markers: The skill instructions do not define clear delimiters or specific instructions for the agent to treat the ingested notice content as passive data, which could lead to the agent following instructions embedded within a notice.
  • Capability inventory: The skill is primarily focused on analytical tasks and report generation; it does not request or demonstrate access to high-risk tools like shell commands, file writing, or network exfiltration.
  • Sanitization: The skill lacks defined sanitization, validation, or filtering logic for the input notices before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:21 AM
Security Audit — agent-trust-hub — dsa-notice-action