hochrisiko-klassifizierung
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, potentially untrusted descriptions of AI systems to perform classification.
- Ingestion points: Untrusted data enters the agent context through the "Eingaben" (Inputs) section in
SKILL.md(e.g., function of the AI system, usage area) and thefact_patternfield intest.md. - Boundary markers: The instructions do not explicitly define delimiters or specific "ignore embedded instructions" warnings for the user-supplied data.
- Capability inventory: The skill is limited to text analysis and output; it does not contain any subprocess calls, file-write operations, or network execution capabilities.
- Sanitization: There is no evidence of input validation or sanitization for the descriptive fields provided by the user.
Audit Metadata