entgelt-auskunftsanspruch
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, specifically the verbatim text of legal requests, employment contracts, and job advertisements as defined in the 'Eingaben' section of SKILL.md. 1) Ingestion points: The skill reads 'Auskunftsverlangen im Wortlaut', 'Bestehende Verschwiegenheitsklauseln', and 'Stellenausschreibungen'. 2) Boundary markers: There are no specific delimiters or instructions defined to prevent the agent from following malicious commands hidden within these ingested texts. 3) Capability inventory: The skill utilizes sub-agents for drafting and research, and executes shell commands for date calculations via an internal CLI tool. 4) Sanitization: No evidence of sanitization or validation of the input text was found in the instructions.
- [COMMAND_EXECUTION]: The skill documentation provides examples of the agent executing a local Python module (scripts.legal_calc.cli) via the shell to calculate legal deadlines based on user input. This represents a controlled use of internal project tooling for the skill's intended functionality.
Audit Metadata