ai-act-triage-pl
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a purely instructional guide for regulatory compliance. It provides a multi-step workflow for classifying systems based on the EU AI Act without requesting sensitive permissions or performing dangerous actions.
- [COMMAND_EXECUTION]: The skill does not contain any shell commands, scripts, or system-level execution patterns. It relies on standard information gathering and processing.
- [DATA_EXFILTRATION]: No exfiltration patterns or hardcoded credentials were found. The skill configuration specifies local data residency and no PII egress, which aligns with the provided instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external information (descriptions of systems to be triaged) and legal texts from EUR-Lex. While this creates an ingestion surface for untrusted data, the skill includes robust mitigation strategies, such as mandatory human approval ('requires-human-approval: true') and explicit instructions to verify all legal references against official sources ('Krok 0').
- [PROMPT_INJECTION]: The instructions do not attempt to bypass safety filters or override agent behavior. The language is consistent with legal triage and compliance auditing.
Audit Metadata