externe-meldung-offenlegung
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user-supplied data in the form of legal fact patterns.
- Ingestion points: The agent accepts user-provided text inputs describing whistleblower scenarios to evaluate legal protections.
- Boundary markers: The instructions do not define explicit delimiters (like XML tags or triple quotes) or provide instructions for the agent to ignore embedded commands within the input data.
- Capability inventory: The skill produces structured text output for legal reporting. No dangerous capabilities such as file writing, network exfiltration, or subprocess command execution were identified in the provided files.
- Sanitization: There is no evidence of input validation, sanitization, or filtering applied to the external fact patterns before they are processed by the agent.
Audit Metadata