cra-vulnerability-obligations
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill interacts with the Ansvar Gateway (
https://gateway.ansvar.eu/mcp) via the Model Context Protocol (MCP) to retrieve legal provisions and vulnerability metadata. This connection is consistent with the skill's primary purpose and author infrastructure. - [PROMPT_INJECTION]: The skill addresses the risk of indirect prompt injection by providing explicit instructions to the agent to treat all tool outputs as data, ignore any instruction-like text returned from the gateway, and follow only a specific allowlist of read-only tools.
- [DATA_EXFILTRATION]: Ground rules explicitly prohibit the transmission of secrets, personal data, source code, or privileged narrative to the external connector. The skill instructs the agent to generalize queries when dealing with non-public vulnerabilities.
Audit Metadata