entgeltberichterstattung
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local Python utility script,
scripts.legal_calc.cli, to perform deterministic legal arithmetic for deadlines and turnus intervals based on the provided inputs. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as payroll records and employee group information, which presents a surface for potential indirect prompt injection. The risk is assessed as low given the structured financial and legal nature of the input data.
- Ingestion points: HR and Payroll system data inputs defined in the 'Eingaben' section of SKILL.md.
- Boundary markers: None present; the instructions do not implement specific delimiters for external data ingestion.
- Capability inventory: Execution of a local command-line Python module.
- Sanitization: No explicit sanitization or input validation logic is defined for the ingested data.
Audit Metadata