gewerbeerlaubnis-34-gewo
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data, creating a potential surface for indirect prompt injection attacks.
- Ingestion points:
SKILL.mdidentifies user-provided activity descriptions, contracts, and legal documents as primary inputs. - Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions embedded within the user data.
- Capability inventory: The skill executes shell commands via a local Python script (
scripts.legal_calc.cli) and generates legal drafts based on input. - Sanitization: No sanitization or validation of the input data is specified before it is processed by the agent or used in command arguments.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local command-line tool using shell syntax to perform legal period calculations. The agent is prompted to construct shell commands incorporating user-supplied dates (e.g.,
--ereignis 01.04.2021), which could lead to command injection if the input is maliciously crafted and not properly validated by the agent prior to execution.
Audit Metadata