eu-ai-act-triage-en

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied descriptions of AI systems to generate triage reports, which is a potential surface for indirect injection.
  • Ingestion points: Facts about the AI system provided by the user during the triage workflow (SKILL.md).
  • Boundary markers: The skill explicitly requires tagging unverified provisions with [check in EUR-Lex] and mandates a "Human gate" for final approval.
  • Capability inventory: Uses the Read tool and the mcp-eu-compliance connector for context retrieval.
  • Sanitization: Requires human-in-the-loop validation (requires-human-approval: true) and verification against authoritative external databases (EUR-Lex) before the output is considered binding.
  • [EXTERNAL_DOWNLOADS]: The skill fetches official legal documentation from a well-known service.
  • Evidence: Accesses Regulation (EU) 2024/1689 (CELEX 32024R1689) from EUR-Lex or via a dedicated compliance connector to ensure legal accuracy.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 11:09 AM
Security Audit — agent-trust-hub — eu-ai-act-triage-en