verbandsklage-zulaessigkeit

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to invoke a local Python module (scripts.legal_calc.cli) for performing legal deadline and financial calculations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external legal data, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Processes user-provided legal complaints (Klageschrift), financial disclosure documents (Mittelherkunft), and third-party financing agreements.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external legal text as untrusted data.
  • Capability inventory: The skill possesses the ability to execute shell commands via a local Python CLI tool.
  • Sanitization: No evidence of input validation, sanitization, or escaping of the external legal documents is present before the data is processed or used by the calculations script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:21 AM
Security Audit — agent-trust-hub — verbandsklage-zulaessigkeit