hausgeldabrechnung
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-provided legal documents (annual statements, economic plans, meeting minutes), which constitutes a surface for indirect prompt injection if the input files contain adversarial instructions designed to manipulate the agent's logic.\n
- Ingestion points: Documented in the 'Eingaben' section of SKILL.md (Wirtschaftsplan, Jahresabrechnung, Einzelabrechnung, MEA-Schlüssel, Beschluss-Sammlung).\n
- Boundary markers: The instructions lack explicit delimiters or specific 'ignore embedded instructions' warnings to separate user-provided data from system instructions.\n
- Capability inventory: Capabilities are restricted to text analysis, research, and drafting using defined sub-agents (researcher, drafter, reviewer) with no high-risk tools listed in allowed-tools.\n
- Sanitization: No content validation or sanitization logic for the imported documents is described in the skill logic.\n- [COMMAND_EXECUTION]: The test documentation references a local command-line operation for evaluation purposes.\n
- Evidence:
python ../../../scripts/eval.py --skill wohnungseigentumsrecht/skills/hausgeldabrechnungfound in test.md.\n - Note: This is an instructional snippet for developers to run local tests and does not represent an automated or remotely-triggerable execution vulnerability.
Audit Metadata