german-elster-tax-filing

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to collect sensitive financial information and PII (Personal Identifiable Information) including income, tax IDs, and family status. This data collection is consistent with the stated purpose of preparing a tax return. No evidence of data exfiltration or unauthorized network operations was found.
  • [SAFE]: The skill provides explicit instructions to use only official government domains (e.g., elster.de, bundesfinanzministerium.de) for information retrieval, ensuring the reliability of the tax law guidance.
  • [SAFE]: There are no indicators of prompt injection, obfuscation, or remote code execution. The workflow is well-defined and focuses on user questioning and tax estimation based on provided documents.
  • [SAFE]: While the skill ingests external data (user documents and receipts), which technically creates an indirect prompt injection surface, the skill lacks any capabilities (such as shell access, network requests, or file-writing tools) that would allow such an injection to be exploited for malicious purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:58 AM
Security Audit — agent-trust-hub — german-elster-tax-filing