verfassungsbeschwerde

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided case facts, which presents a surface for indirect prompt injection where malicious instructions could be embedded in the case description.
  • Ingestion points: User-supplied inputs such as the 'gerügter Hoheitsakt', 'Verfahrensstand', and 'Beschwerdeführer' details in 'SKILL.md', as well as the 'fact_pattern' in 'test.md'.
  • Boundary markers: Absent; there are no specific delimiters defined to separate user input from system instructions.
  • Capability inventory: Limited to text generation (legal drafting and research summaries). No unsafe file system access, network exfiltration, or code execution capabilities were identified.
  • Sanitization: No input validation or filtering of user-provided legal facts is specified.
  • Remediation: Use clear delimiters (e.g., XML tags) around user input and include instructions for the agent to ignore any command-like text within those boundaries.
  • [SAFE]: All external URL references are to official German legislation portals (gesetze-im-internet.de), the Federal Constitutional Court (bundesverfassungsgericht.de), and academic legal databases (servat.unibe.ch).
  • [SAFE]: No obfuscation techniques, hardcoded credentials, or unauthorized persistence mechanisms were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 08:41 AM
Security Audit — agent-trust-hub — verfassungsbeschwerde