gdpr-dsgvo-expert
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources as part of its primary functionality, creating a potential surface for indirect prompt injection if malicious instructions are embedded in scanned files.
- Ingestion points: The
scripts/gdpr_compliance_checker.pyscript recursively scans project directories and reads the content of files with common code and configuration extensions. Thescripts/dpia_generator.pyscript reads user-provided JSON input files. - Boundary markers: The scripts output findings directly to the console or structured JSON files without specific delimiters or instructions to the agent to ignore embedded commands.
- Capability inventory: The skill scripts are limited to local filesystem read/write operations for generating reports and tracking requests; they do not possess network or shell-execution capabilities.
- Sanitization: Content is processed via regular expressions and JSON parsing, but no specific sanitization is performed to prevent the LLM from following instructions potentially contained within the scanned data.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration mechanisms were detected. The skill's behavior aligns strictly with its stated purpose of privacy compliance automation.
Audit Metadata