audit-rgpd-site-internet
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a professional auditing framework with clear operational boundaries. It includes a 'Garde-fous de conformité' section that explicitly prohibits providing legal advice, modifying the target site, or performing security testing (pentesting).
- [DATA_EXFILTRATION]: The instructions contain robust privacy protection rules. The agent is explicitly told to ignore and not reproduce any personal data (PII) such as emails or names found on the audited sites, and instead use generic terms in reports.
- [INDIRECT_PROMPT_INJECTION]: Because the skill processes content from untrusted external URLs, it technically possesses an indirect prompt injection attack surface. However, this is inherent to its primary function as a web auditor. The risk is significantly mitigated by the 'Règle de non-hallucination' and structured checklist requirements which force the agent to treat website content as data rather than instructions.
- [COMMAND_EXECUTION]: No unauthorized command execution or subprocess spawning patterns were detected. The skill uses standard platform-provided browsing tools for its audit tasks.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or attempts to access local sensitive files (like SSH keys or environment variables) were found.
Audit Metadata