privacy-notice-generator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for legal documentation and compliance checking. It consists of reference guides and two Python scripts (privacy_notice_scaffolder.py and notice_compliance_checker.py) that operate entirely on local text data.\n- [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection as notice_compliance_checker.py ingests untrusted privacy notice text from external files. However, the risk is negligible as the script's capabilities are limited to regex-based analysis and text reporting.\n
  • Ingestion points: scripts/notice_compliance_checker.py reads content from a user-provided file path.\n
  • Boundary markers: Absent; the script processes the full text of the provided file.\n
  • Capability inventory: Limited to file reading, string searching (regex), and printing analysis results to standard output. No network or shell execution capabilities were detected.\n
  • Sanitization: Absent; the script does not escape or sanitize the input text before processing, but its logic is non-executable.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:55 PM
Security Audit — agent-trust-hub — privacy-notice-generator