interne-meldung-bearbeitung
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process whistleblower reports ('Meldung'), which constitutes a surface for indirect prompt injection where malicious instructions could be embedded in the submitted text.
- Ingestion points: Untrusted data enters the agent context through the 'Meldung' input parameter defined in SKILL.md.
- Boundary markers: The instructions do not define delimiters or provide specific warnings to the agent to ignore instructions embedded within the processed content.
- Capability inventory: The skill identifies procedural steps and formats output but does not include high-risk capabilities such as arbitrary command execution, network exfiltration, or file system modifications.
- Sanitization: There are no documented procedures for sanitizing or escaping the content of the incoming whistleblower reports before they are processed by the agent.
- [SAFE]: The skill provides references to legal documentation from official government domains (gesetze-im-internet.de) and European Union legal repositories (eur-lex.europa.eu). The test file also mentions a local python execution command for evaluation purposes, which is a standard development practice.
Audit Metadata