reisevermittlung-informationspflichten

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as booking details, AGBs, and correspondence, which could contain malicious instructions designed to influence the agent's legal analysis.
  • Ingestion points: Defined in SKILL.md under the "Eingaben" section, specifically for items like "Buchungsbestätigung", "AGB", and "Schriftverkehr".
  • Boundary markers: The skill instructions do not define specific delimiters or "ignore embedded instructions" warnings for the agent when processing user-provided documents.
  • Capability inventory: The skill uses a multi-agent architecture (researcher, drafter, reviewer) to perform legal subsumption and draft formal claim letters.
  • Sanitization: No explicit content sanitization, validation, or filtering of external legal content is described in the provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:21 AM
Security Audit — agent-trust-hub — reisevermittlung-informationspflichten