kyc-identifikationspflicht

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data provided by a user (business transaction details, corporate ownership structures, and identities). While there are no specific boundary markers or sanitization logic defined in the markdown, the primary capability is drafting a legal memo. The risk is low as it does not perform automated shell execution or file system writes based on this data.
  • [SAFE]: The skill references established, well-known legal and government resources for regulatory information, such as 'gesetze-im-internet.de' and 'eur-lex.europa.eu'. These are used appropriately for legal research and compliance guidance.
  • [SAFE]: The test file references a local Python evaluation script for testing purposes, which is a standard development practice for skill validation and does not involve remote code execution from unknown sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:21 AM
Security Audit — agent-trust-hub — kyc-identifikationspflicht