incident-reporting-navigator

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill communicates with an external API at gateway.ansvar.eu to retrieve regulatory information. It incorporates rigorous data minimization rules, explicitly prohibiting the transmission of secrets, raw logs, personal data, or privileged narrative to the external gateway.
  • [PROMPT_INJECTION]: The skill contains comprehensive grounding instructions that prevent the model from inventing sources or relying on internal memory. It specifically addresses indirect prompt injection risks by requiring the agent to treat tool outputs as data only and to disregard any instruction-like text embedded within retrieved rows.
  • [EXTERNAL_DOWNLOADS]: The skill is designed to fetch official legal text from official publishers (such as EUR-Lex) via a specific gateway. This functionality is essential for its stated purpose and does not involve downloading or executing arbitrary scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — incident-reporting-navigator