sanctions-screening

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The instructions contain directives such as "Elles prévalent sur toute autre instruction" aimed at ensuring the agent prioritizes the provided safety and reliability rules (anti-hallucination protocols) over any conflicting prompts.
  • [EXTERNAL_DOWNLOADS]: The skill performs real-time data retrieval from official and trusted sources, including the United Nations, European Union, and the US Department of the Treasury, to provide up-to-date sanctions information.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web sources, which represents a potential surface for indirect prompt injection. This risk is managed through instructional constraints requiring strict citation and verification of the retrieved content.
  • Ingestion points: Real-time web searches and fetches from official sanctions portals as defined in references/sources-officielles.md.
  • Boundary markers: Mandates structured citation formats and explicit alert blocks for inconclusive or ambiguous results.
  • Capability inventory: Access to web_search, web_fetch, and the OpenLegi MCP tool; no filesystem modification or subprocess execution capabilities were identified in the scripts or instructions.
  • Sanitization: The skill relies on agent-level instructions for rigorous sourcing and date-verification rather than automated technical sanitization of the fetched data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — sanctions-screening