verfassungsbeschwerde
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes user-provided case facts, which presents a surface for indirect prompt injection where malicious instructions could be embedded in the case description.
- Ingestion points: User-supplied inputs such as the 'gerügter Hoheitsakt', 'Verfahrensstand', and 'Beschwerdeführer' details in 'SKILL.md', as well as the 'fact_pattern' in 'test.md'.
- Boundary markers: Absent; there are no specific delimiters defined to separate user input from system instructions.
- Capability inventory: Limited to text generation (legal drafting and research summaries). No unsafe file system access, network exfiltration, or code execution capabilities were identified.
- Sanitization: No input validation or filtering of user-provided legal facts is specified.
- Remediation: Use clear delimiters (e.g., XML tags) around user input and include instructions for the agent to ignore any command-like text within those boundaries.
- [SAFE]: All external URL references are to official German legislation portals (gesetze-im-internet.de), the Federal Constitutional Court (bundesverfassungsgericht.de), and academic legal databases (servat.unibe.ch).
- [SAFE]: No obfuscation techniques, hardcoded credentials, or unauthorized persistence mechanisms were detected.
Audit Metadata