privacy-eu
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user input during a legal interview phase to populate code and documentation templates. • Ingestion points: User responses to interview questions defined in SKILL.md and scripts/interview.md. • Boundary markers: No explicit delimiters or instructions are used to separate user data from the generated code logic. • Capability inventory: The skill writes several .mdx and .tsx files to the local src/ directory based on user input. • Sanitization: No input validation or escaping mechanisms are specified to ensure user-provided strings do not contain malicious code or formatting.
- [EXTERNAL_DOWNLOADS]: The skill references the official European Commission Online Dispute Resolution (ODR) portal. This is a well-known official service used for its intended compliance purpose and does not represent a security risk.
Audit Metadata