privacy-kr

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an indirect prompt injection surface by collecting user data during a multi-step interview and using it to populate code and documentation templates.\n
  • Ingestion points: User answers from the '인터뷰 범위' (Interview Range) defined in SKILL.md (Steps 1-11).\n
  • Boundary markers: Absent; there are no instructions to the agent to sanitize user data or isolate it within the templates.\n
  • Capability inventory: The skill generates and writes multiple .tsx and .mdx files to the filesystem (e.g., src/app/privacy/page.tsx, src/components/legal/ConsentModal.tsx).\n
  • Sanitization: Absent; the skill does not specify any escaping or validation of user-provided strings before they are rendered into templates.\n- [COMMAND_EXECUTION]: The skill performs file system modifications and code generation via the scripts/render.md and scripts/install.md protocols, which involve creating and placing generated code files into the user's project structure.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 05:04 AM
Security Audit — agent-trust-hub — privacy-kr