verbraucherwiderruf

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data concerning contract details, delivery dates, and the specific content of withdrawal declarations, which may be susceptible to indirect prompt injection.
  • Ingestion points: The skill ingests user input across several fields defined in the 'Eingaben' section of SKILL.md, including party roles and withdrawal contents.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard potentially malicious commands embedded within the user's contract data.
  • Capability inventory: The skill leverages sub-agents (researcher, drafter, reviewer) and possesses the ability to execute a local Python calculation script.
  • Sanitization: The instructions do not define any sanitization, filtering, or validation steps for the external content before it is processed.
  • [COMMAND_EXECUTION]: The skill relies on the execution of a local Python module to perform deterministic date calculations based on user input.
  • Evidence: The skill specifies the use of python -m scripts.legal_calc.cli in the 'Deterministische Berechnung' section of SKILL.md to calculate legal deadlines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:20 AM
Security Audit — agent-trust-hub — verbraucherwiderruf