regulatory-threat-model

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Connects to the Ansvar Gateway MCP connector at https://gateway.ansvar.eu/mcp to perform security analysis and fetch regulatory data.
  • [DATA_EXFILTRATION]: Sends architecture-level summaries to the external domain ansvar.eu. The instructions explicitly prohibit sending source code, secrets, or personally identifiable information, requiring user verification before transmission.
  • [PROMPT_INJECTION]: The skill addresses potential indirect prompt injection by instructing the agent to treat all tool outputs (ingestion points: search_cve, get_provision, workflow results) as untrusted data. Rule 2 serves as a boundary marker defining the control plane vs. data boundary. The capability inventory is restricted to specific MCP tool calls, and sanitization is enforced by requiring the agent to build tool arguments from verified intake facts or user-confirmed data.
  • [REMOTE_CODE_EXECUTION]: Orchestrates remote tool calls via the Ansvar Gateway's MCP endpoint for STRIDE and LINDDUN modeling. The agent is limited to a pre-defined set of verified tool schemas.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — regulatory-threat-model