hochrisiko-klassifizierung

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, potentially untrusted descriptions of AI systems to perform classification.
  • Ingestion points: Untrusted data enters the agent context through the "Eingaben" (Inputs) section in SKILL.md (e.g., function of the AI system, usage area) and the fact_pattern field in test.md.
  • Boundary markers: The instructions do not explicitly define delimiters or specific "ignore embedded instructions" warnings for the user-supplied data.
  • Capability inventory: The skill is limited to text analysis and output; it does not contain any subprocess calls, file-write operations, or network execution capabilities.
  • Sanitization: There is no evidence of input validation or sanitization for the descriptive fields provided by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:20 AM
Security Audit — agent-trust-hub — hochrisiko-klassifizierung