gwg-risikoanalyse
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it processes user-provided data. 1. Ingestion points: The skill accepts business models and existing risk analyses as input in SKILL.md. 2. Boundary markers: No delimiters are used to separate user data from instructions. 3. Capability inventory: The skill is limited to text generation and drafting via sub-agents. 4. Sanitization: There are no explicit instructions for the agent to sanitize or ignore instructions within the user-provided inputs.
- [COMMAND_EXECUTION]: The test.md file contains a reference to a local evaluation script (python eval.py) intended for internal testing.
- [EXTERNAL_DOWNLOADS]: The skill references official legal resources from well-known domains including gesetze-im-internet.de and eur-lex.europa.eu for compliance research purposes.
Audit Metadata