verbraucherwiderruf
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data concerning contract details, delivery dates, and the specific content of withdrawal declarations, which may be susceptible to indirect prompt injection.
- Ingestion points: The skill ingests user input across several fields defined in the 'Eingaben' section of SKILL.md, including party roles and withdrawal contents.
- Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard potentially malicious commands embedded within the user's contract data.
- Capability inventory: The skill leverages sub-agents (researcher, drafter, reviewer) and possesses the ability to execute a local Python calculation script.
- Sanitization: The instructions do not define any sanitization, filtering, or validation steps for the external content before it is processed.
- [COMMAND_EXECUTION]: The skill relies on the execution of a local Python module to perform deterministic date calculations based on user input.
- Evidence: The skill specifies the use of
python -m scripts.legal_calc.cliin the 'Deterministische Berechnung' section of SKILL.md to calculate legal deadlines.
Audit Metadata