kyc-identifikationspflicht
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data provided by a user (business transaction details, corporate ownership structures, and identities). While there are no specific boundary markers or sanitization logic defined in the markdown, the primary capability is drafting a legal memo. The risk is low as it does not perform automated shell execution or file system writes based on this data.
- [SAFE]: The skill references established, well-known legal and government resources for regulatory information, such as 'gesetze-im-internet.de' and 'eur-lex.europa.eu'. These are used appropriately for legal research and compliance guidance.
- [SAFE]: The test file references a local Python evaluation script for testing purposes, which is a standard development practice for skill validation and does not involve remote code execution from unknown sources.
Audit Metadata