brazil-records-requests

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [PROMPT_INJECTION]: No malicious injection patterns or safety bypass attempts were detected. The skill provides functional instructions for the agent to draft content in Portuguese and advises users on legal strategies for records requests, which are consistent with its educational purpose.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill does not access sensitive local files or hardcoded credentials. It references official Brazilian government domains (e.g., portaltransparencia.gov.br, falabr.cgu.gov.br) and a well-known transparency archive (achadosepedidos.org.br) for legitimate research purposes.
  • [OBFUSCATION]: No Base64, zero-width characters, homoglyphs, or other obfuscation techniques were found in any of the analyzed files.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill contains no executable scripts (Python, JS, Shell) or package manifests. It is composed exclusively of Markdown templates and YAML metadata.
  • [INDIRECT_PROMPT_INJECTION]: Although the skill processes user input to populate legal templates, it lacks the necessary capabilities (such as network operations or file system access) to be exploited via indirect injection vectors.
  • [DYNAMIC_CONTEXT_INJECTION]: No load-time shell execution commands or dynamic context injection patterns were identified in the SKILL.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 11:22 PM
Security Audit — agent-trust-hub — brazil-records-requests