vergabe-eu-schwellenwert-pruefung

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted user data regarding procurement details.
  • Ingestion points: Data is entered via fields like 'Auftragsgegenstand' (object of contract) and 'Eingaben' in SKILL.md, as well as the 'fact_pattern' in test.md.
  • Boundary markers: The instructions do not define strict delimiters or include 'ignore embedded instructions' warnings for the data it processes.
  • Capability inventory: The skill is limited to text-based legal analysis and report generation. It does not contain scripts for file system modification, network communication, or system command execution.
  • Sanitization: No explicit sanitization, filtering, or escaping of the user-provided text is performed before processing.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to official legal and judicial databases for regulatory reference.
  • Evidence: The skill references curia.europa.eu, gesetze-im-internet.de, and eur-lex.europa.eu.
  • Analysis: These domains are official portals for the Court of Justice of the European Union, the German Federal Ministry of Justice, and EU law, respectively.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 08:40 AM
Security Audit — agent-trust-hub — vergabe-eu-schwellenwert-pruefung