sota-privacy-compliance
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data sources such as codebases, database schemas, and application logs to identify privacy and compliance gaps. This creates a surface for indirect prompt injection if the analyzed content contains malicious instructions intended to mislead the agent or bypass its safety protocols.
- Ingestion points: The AUDIT mode in SKILL.md and discovery patterns in rules/01 involve reading untrusted data from schemas, API payloads, log statements, and analytics events.
- Boundary markers: The instructions do not define specific delimiters or warnings to separate the analyzed content from the agent's instructions, increasing the risk of the agent obeying embedded commands.
- Capability inventory: The skill allows the agent to read and summarize file contents, identify sensitive data, and provide remediation guidance based on its findings.
- Sanitization: There are no requirements or patterns for sanitizing, escaping, or filtering the external content before it is processed by the agent.
Audit Metadata