807-regulations-eu-digital-services-act
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes user-provided Java code and configurations (Workflow Step 3 in SKILL.md), which creates an inherent surface for indirect prompt injection if the analyzed content contains malicious instructions intended to mislead the agent. The skill partially mitigates this risk by instructing the agent to focus on specific DSA controls and follow a rigid report template.
- Ingestion points: Identified in SKILL.md Workflow Step 3.
- Boundary markers: Not explicitly defined for the code analysis phase.
- Capability inventory: Restricted to analysis and reporting based on provided templates.
- Sanitization: Instructions promote privacy-safe logging and redaction of sensitive data as seen in the engineering examples.
Audit Metadata