skills/goul4rt/lgpd-skills/lgpd-ropa/Gen Agent Trust Hub

lgpd-ropa

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to read internal documentation files from the .lgpd/ directory and generate a consolidated report based on a local template. All operations are confined to the local file system.
  • [DATA_EXFILTRATION]: There are no network operations, such as curl, wget, or API requests, that would allow data to be transmitted externally. All processing is performed locally within the project context.
  • [PROMPT_INJECTION]: The instructions focus purely on the workflow for data consolidation and formatting. There are no attempts to override agent behavior, bypass safety filters, or extract system prompts.
  • [REMOTE_CODE_EXECUTION]: The skill does not download external scripts, install third-party packages, or use dynamic execution functions like eval() or exec().
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted data from .lgpd/data-map.md and .lgpd/legal-basis.md (Ingestion Points), the output is written to a markdown file (.lgpd/ROPA.md) and the skill possesses no high-risk capabilities like network access or subprocess execution (Capability Inventory). The risk of embedded instructions in the source files influencing the agent to perform malicious actions is negligible in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:52 PM
Security Audit — agent-trust-hub — lgpd-ropa