interne-meldung-bearbeitung

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process whistleblower reports ('Meldung'), which constitutes a surface for indirect prompt injection where malicious instructions could be embedded in the submitted text.
  • Ingestion points: Untrusted data enters the agent context through the 'Meldung' input parameter defined in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or provide specific warnings to the agent to ignore instructions embedded within the processed content.
  • Capability inventory: The skill identifies procedural steps and formats output but does not include high-risk capabilities such as arbitrary command execution, network exfiltration, or file system modifications.
  • Sanitization: There are no documented procedures for sanitizing or escaping the content of the incoming whistleblower reports before they are processed by the agent.
  • [SAFE]: The skill provides references to legal documentation from official government domains (gesetze-im-internet.de) and European Union legal repositories (eur-lex.europa.eu). The test file also mentions a local python execution command for evaluation purposes, which is a standard development practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:20 AM
Security Audit — agent-trust-hub — interne-meldung-bearbeitung