gwg-risikoanalyse

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data such as business models, customer group descriptions, and existing risk analyses to generate legal documentation. This creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions intended to influence the agent's output.
  • Ingestion points: Ingests data through the 'Eingaben' section in SKILL.md, including business models, customer groups, and existing risk assessments.
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions to ignore embedded commands in the user-provided data.
  • Capability inventory: The skill utilizes text generation and research agents (researcher, drafter, reviewer) to produce documentation. No dangerous system-level capabilities are identified in the skill instructions.
  • Sanitization: Absent. There are no explicit filtering or sanitization steps mentioned for the input data.
  • [COMMAND_EXECUTION]: The skill documentation includes a command for local script execution for testing purposes.
  • Evidence: A shell command python ../../../scripts/eval.py --skill ... is present in test.md. This is a standard testing instruction and uses a relative path to a local repository script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:22 AM
Security Audit — agent-trust-hub — gwg-risikoanalyse