dpa-art-28-oliver-schmidt-prietz

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions do not contain any patterns attempting to override agent behavior or bypass safety filters. The instructions are focused entirely on the legal analysis of Data Processing Agreements.
  • [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were detected. External links included in the documentation point to trusted domains such as 'eur-lex.europa.eu' and the author's website 'onezero.legal'.
  • [COMMAND_EXECUTION]: The skill does not instruct the agent to execute any dangerous shell commands. Deployment instructions provided in the README are limited to standard file operations for local setup.
  • [EXTERNAL_DOWNLOADS]: No remote code or scripts are downloaded or executed. The reference materials are stored locally as markdown files.
  • [REMOTE_CODE_EXECUTION]: There are no patterns for remote code execution, piped shell scripts, or dynamic code generation. The skill operates entirely through natural language processing of provided legal templates.
  • [NO_CODE]: The skill package consists solely of text-based configuration, documentation, and templates. No binary or script files are included.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted user data (external DPAs), it lacks the capabilities (such as file-writing or network tools) that could be exploited via indirect prompt injection. The risk is limited to the accuracy of the agent's legal review.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:32 PM
Security Audit — agent-trust-hub — dpa-art-28-oliver-schmidt-prietz