hausgeldabrechnung

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-provided legal documents (annual statements, economic plans, meeting minutes), which constitutes a surface for indirect prompt injection if the input files contain adversarial instructions designed to manipulate the agent's logic.\n
  • Ingestion points: Documented in the 'Eingaben' section of SKILL.md (Wirtschaftsplan, Jahresabrechnung, Einzelabrechnung, MEA-Schlüssel, Beschluss-Sammlung).\n
  • Boundary markers: The instructions lack explicit delimiters or specific 'ignore embedded instructions' warnings to separate user-provided data from system instructions.\n
  • Capability inventory: Capabilities are restricted to text analysis, research, and drafting using defined sub-agents (researcher, drafter, reviewer) with no high-risk tools listed in allowed-tools.\n
  • Sanitization: No content validation or sanitization logic for the imported documents is described in the skill logic.\n- [COMMAND_EXECUTION]: The test documentation references a local command-line operation for evaluation purposes.\n
  • Evidence: python ../../../scripts/eval.py --skill wohnungseigentumsrecht/skills/hausgeldabrechnung found in test.md.\n
  • Note: This is an instructional snippet for developers to run local tests and does not represent an automated or remotely-triggerable execution vulnerability.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:21 AM
Security Audit — agent-trust-hub — hausgeldabrechnung