analyse-dpa-fournisseur-hugo-salard

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill serves as a template-based audit tool for Data Processing Agreements. It contains no executable code, binaries, or shell scripts. The routing logic directs the agent to internal markdown files for reference, maintaining a closed execution environment.- [PROMPT_INJECTION]: The skill processes untrusted third-party documents (DPAs) as its primary input, creating a surface for indirect prompt injection. A malicious contract could attempt to manipulate the audit outcome or the agent's behavior. However, the risk is mitigated by the lack of any actionable tools (e.g., shell access, network requests, or file writes) within the skill's scope. The skill relies entirely on the underlying agent's safety guardrails when processing the provided text.
  • Ingestion points: User-provided DPA content in PDF, text, or DOCX format identified in Step 1 of SKILL.md.
  • Boundary markers: The instructions lack explicit security delimiters or 'ignore' instructions for the external content.
  • Capability inventory: Zero tools or commands; the skill is restricted to text analysis.
  • Sanitization: Not applicable as no data is passed to external systems or used in command construction.- [SAFE]: No obfuscation (Base64, zero-width characters, or homoglyphs) was detected in the skill instructions or resources. The metadata and author information appear legitimate and consistent with the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — analyse-dpa-fournisseur-hugo-salard