gwg-risikoanalyse
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data such as business models, customer group descriptions, and existing risk analyses to generate legal documentation. This creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions intended to influence the agent's output.
- Ingestion points: Ingests data through the 'Eingaben' section in SKILL.md, including business models, customer groups, and existing risk assessments.
- Boundary markers: Absent. The skill does not define specific delimiters or instructions to ignore embedded commands in the user-provided data.
- Capability inventory: The skill utilizes text generation and research agents (researcher, drafter, reviewer) to produce documentation. No dangerous system-level capabilities are identified in the skill instructions.
- Sanitization: Absent. There are no explicit filtering or sanitization steps mentioned for the input data.
- [COMMAND_EXECUTION]: The skill documentation includes a command for local script execution for testing purposes.
- Evidence: A shell command
python ../../../scripts/eval.py --skill ...is present in test.md. This is a standard testing instruction and uses a relative path to a local repository script.
Audit Metadata