ai-content-disclosure
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill includes two Python scripts,
scripts/disclosure_checker.pyandscripts/review_authenticity_linter.py, which are used for compliance checking. Both scripts utilize only the Python standard library and do not perform any network operations, file system modifications, or command executions. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content via JSON manifest and review files.
- Ingestion points: The scripts
scripts/disclosure_checker.pyandscripts/review_authenticity_linter.pyread data from user-supplied JSON files specified at runtime. - Boundary markers: Data is structured using JSON, which provides clear boundaries between different fields.
- Capability inventory: The scripts are limited to processing text and printing findings to the standard output. They do not have capabilities for network access, arbitrary file writing, or subprocess execution.
- Sanitization: While the scripts use regular expressions to identify patterns, they do not explicitly sanitize content before it is read by the AI agent. However, given the lack of dangerous capabilities in the scripts, the risk of exploitation is negligible.
- [SAFE]: The skill references reputable and well-known regulatory sources (e.g., eur-lex.europa.eu, ftc.gov) for its compliance logic. These references are used legitimately to provide decision support for marketing disclosures.
Audit Metadata