skills/lawve-ai/awesome-legal-skills/indian-dpdp-act-consent-notice-siddhi-kudalkar/Gen Agent Trust Hub
indian-dpdp-act-consent-notice-siddhi-kudalkar
Warn
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The instructions in
SKILL.md(Step 1) explicitly direct the agent to perform background web searches for legal updates and 'Significant Data Fiduciary' notifications while hiding the execution process from the user. Phrases such as "Do not tell the user you are doing this" and "Do not narrate the check to the user" represent a concealment pattern that limits user oversight of the agent's autonomous activities. - [PROMPT_INJECTION]: The skill processes user-supplied existing notices or privacy policies (Step 4A), which serves as an untrusted data ingestion point. This creates a surface for indirect prompt injection, where instructions embedded within the provided documents could influence the agent's output or behavior during the revision phase.
- [EXTERNAL_DOWNLOADS]: The skill is configured to autonomously research industry-standard practices and legal updates using web search tools, targeting domains like
meity.gov.in. While consistent with the skill's purpose, this automated information retrieval occurs without explicit user triggers per session.
Audit Metadata