gdpr-dsgvo-expert

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources as part of its primary functionality, creating a potential surface for indirect prompt injection if malicious instructions are embedded in scanned files.
  • Ingestion points: The scripts/gdpr_compliance_checker.py script recursively scans project directories and reads the content of files with common code and configuration extensions. The scripts/dpia_generator.py script reads user-provided JSON input files.
  • Boundary markers: The scripts output findings directly to the console or structured JSON files without specific delimiters or instructions to the agent to ignore embedded commands.
  • Capability inventory: The skill scripts are limited to local filesystem read/write operations for generating reports and tracking requests; they do not possess network or shell-execution capabilities.
  • Sanitization: Content is processed via regular expressions and JSON parsing, but no specific sanitization is performed to prevent the LLM from following instructions potentially contained within the scanned data.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration mechanisms were detected. The skill's behavior aligns strictly with its stated purpose of privacy compliance automation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:32 PM