cra-vulnerability-obligations

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the Ansvar Gateway (https://gateway.ansvar.eu/mcp) via the Model Context Protocol (MCP) to retrieve legal provisions and vulnerability metadata. This connection is consistent with the skill's primary purpose and author infrastructure.
  • [PROMPT_INJECTION]: The skill addresses the risk of indirect prompt injection by providing explicit instructions to the agent to treat all tool outputs as data, ignore any instruction-like text returned from the gateway, and follow only a specific allowlist of read-only tools.
  • [DATA_EXFILTRATION]: Ground rules explicitly prohibit the transmission of secrets, personal data, source code, or privileged narrative to the external connector. The skill instructs the agent to generalize queries when dealing with non-public vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:32 PM
Security Audit — agent-trust-hub — cra-vulnerability-obligations