irrefuehrende-werbung-pruefung

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several external URLs for legal statutes and case law. These target well-known official services: gesetze-im-internet.de (German Federal Ministry of Justice) and eur-lex.europa.eu (Official portal for European Union law). These references are legitimate and do not involve executable code.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8).
  • Ingestion points: The skill is designed to ingest and process untrusted user data in the form of 'konkrete Werbeaussage' (specific advertising statements) as defined in the 'Eingaben' section of SKILL.md.
  • Boundary markers: There are no explicit instructions to the agent to treat this specific input as untrusted or to use delimiters to prevent embedded instructions from influencing agent behavior.
  • Capability inventory: While no dangerous system tools (like shell execution or file writing) are requested in the YAML frontmatter, the 'drafter' and 'reviewer' agents generate structured legal documents, including 'Abmahnentwurf' (cease-and-desist drafts), which could be manipulated by adversarial text within the processed advertising statement.
  • Sanitization: There is no evidence of sanitization or filtering of the input advertising copy before it is processed by the sub-agent architecture.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 08:40 AM
Security Audit — agent-trust-hub — irrefuehrende-werbung-pruefung