ai-data-privacy
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional, providing a methodology for reviewing AI system privacy. It does not include executable code, scripts, or network-enabled operations. All tool use is restricted to read-only filesystem commands (Read, Grep, Glob).
- [PROMPT_INJECTION]: The skill contains a dedicated 'Prompt Injection Safety Notice' advising the agent to treat reviewed content as data rather than instructions. This proactively mitigates indirect prompt injection risks by explicitly instructing the agent to ignore behavior-changing commands found in target files.
- [EXTERNAL_DOWNLOADS]: No external resources or code are downloaded. All URL references point to reputable organizations and well-known documentation services (NIST, OWASP, EUR-Lex) for informational purposes.
- [DATA_EXFILTRATION]: There are no indicators of data exfiltration. The skill defines data flow maps and grep patterns purely to assist the auditor in identifying sensitive data handling within the target application.
Audit Metadata