nis2-ksc-pl
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a structured framework for legal triage regarding the NIS2 Directive and the Polish National Cybersecurity System (KSC). It focuses on informational analysis and explicitly disclaims automated reporting or technical verification.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided information about organizational sectors and size to perform its triage logic. While this creates a data ingestion surface, the skill's restricted capabilities (primarily using the
Readtool and fetching data from official legal databases) and the requirement for human oversight mitigate the risk of malicious input influencing system behavior beyond the generated report. - [EXTERNAL_DOWNLOADS]: The instructions mandate checking the status of Polish legislation via official connectors to the ISAP (Sejm) and EUR-Lex databases. These are trusted, well-known sources for legislative data and do not represent a security risk or remote code execution threat.
Audit Metadata