uk-gdpr
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites to perform its audit, creating a surface for indirect prompt injection attacks.
- Ingestion points: The skill reads and analyzes content from user-provided URLs, specifically targeting privacy policies, cookie policies, and legal pages (SKILL.md, Paso 1).
- Boundary markers: The instructions lack specific delimiters or guardrails to prevent the agent from obeying instructions that might be hidden within the text of the audited websites.
- Capability inventory: The agent has the capability to generate and save documents to the local file system at hardcoded paths (SKILL.md, Paso 6).
- Sanitization: There is no evidence of sanitization or filtering applied to the external content before it is processed by the AI for scoring and reporting.
Audit Metadata