sota-privacy-compliance

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data sources such as codebases, database schemas, and application logs to identify privacy and compliance gaps. This creates a surface for indirect prompt injection if the analyzed content contains malicious instructions intended to mislead the agent or bypass its safety protocols.
  • Ingestion points: The AUDIT mode in SKILL.md and discovery patterns in rules/01 involve reading untrusted data from schemas, API payloads, log statements, and analytics events.
  • Boundary markers: The instructions do not define specific delimiters or warnings to separate the analyzed content from the agent's instructions, increasing the risk of the agent obeying embedded commands.
  • Capability inventory: The skill allows the agent to read and summarize file contents, identify sensitive data, and provide remediation guidance based on its findings.
  • Sanitization: There are no requirements or patterns for sanitizing, escaping, or filtering the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 12:02 AM
Security Audit — agent-trust-hub — sota-privacy-compliance