dpa-art-28-oliver-schmidt-prietz
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions do not contain any patterns attempting to override agent behavior or bypass safety filters. The instructions are focused entirely on the legal analysis of Data Processing Agreements.
- [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were detected. External links included in the documentation point to trusted domains such as 'eur-lex.europa.eu' and the author's website 'onezero.legal'.
- [COMMAND_EXECUTION]: The skill does not instruct the agent to execute any dangerous shell commands. Deployment instructions provided in the README are limited to standard file operations for local setup.
- [EXTERNAL_DOWNLOADS]: No remote code or scripts are downloaded or executed. The reference materials are stored locally as markdown files.
- [REMOTE_CODE_EXECUTION]: There are no patterns for remote code execution, piped shell scripts, or dynamic code generation. The skill operates entirely through natural language processing of provided legal templates.
- [NO_CODE]: The skill package consists solely of text-based configuration, documentation, and templates. No binary or script files are included.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted user data (external DPAs), it lacks the capabilities (such as file-writing or network tools) that could be exploited via indirect prompt injection. The risk is limited to the accuracy of the agent's legal review.
Audit Metadata