lgpd-legal-basis

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to process data from external sources (specifically inputs from 'lgpd-data-mapping') and interpolate it into legal documentation templates.
  • Ingestion points: Data input coming from lgpd-data-mapping referenced in the workflow section of SKILL.md.
  • Boundary markers: The skill does not implement delimiters or 'ignore embedded instructions' warnings for the data it processes.
  • Capability inventory: The skill performs file-write operations to the .lgpd/ directory as specified in SKILL.md.
  • Sanitization: No validation or sanitization of the input data is provided before its use in generating the .lgpd/legal-basis.md or .lgpd/lia/*.md files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:52 PM
Security Audit — agent-trust-hub — lgpd-legal-basis