giz-eu-local-procurement-response
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a structured framework for responding to GIZ local procurement tenders. Its primary functions include building compliance matrices, running eligibility scans, and managing two-envelope submission architectures.
- [SAFE]: The skill uses read and search capabilities to inspect local tender packs and CV evidence. These operations are used for defensive purposes, such as scanning technical bids for prohibited price information to prevent administrative rejection.
- [SAFE]: No indicators of prompt injection, data exfiltration, unauthorized network activity, or persistence mechanisms were detected. The workflow includes explicit handoff points for human review and signatory approval.
- [SAFE]: The skill mentions external data ingestion (tender packs and personnel records), which represents an entry point for indirect prompt injection. However, since the skill does not possess high-privilege capabilities such as remote code execution or network exfiltration, this surface is considered a standard operational requirement for its function.
Audit Metadata