nis2-risikomanagement

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data regarding a company's infrastructure and compliance status. * Ingestion points: Inputs like 'Einordnung der Einrichtung', 'Inventar kritischer Systeme', and 'Notfallkonzepte' are provided by the user in SKILL.md. * Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings for the data being analyzed. * Capability inventory: The skill involves logic for gap analysis and roadmap generation across the Sub-Agent-Architektur defined in SKILL.md. * Sanitization: No sanitization or validation of the provided organizational details is specified before interpolation into the analysis prompt.
  • [SAFE]: The skill references official legal documentation from well-known services, such as gesetze-im-internet.de and eur-lex.europa.eu, to provide context for the NIS2 risk assessment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:20 AM
Security Audit — agent-trust-hub — nis2-risikomanagement