uodo-grounding-pl
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Node.js runtime to execute a shared verification engine (
ground-citations.mjs) located in a companion skill folder. This is a legitimate architectural pattern for code reuse across legal grounding tools. - [EXTERNAL_DOWNLOADS]: The skill performs targeted network requests to
uodo.gov.pland official EU legal databases viaWebFetchto retrieve decision texts. These operations are performed on well-known government services and are necessary for the skill's primary function. - [PROMPT_INJECTION]: The skill ingests external content from official websites and user-provided documents, creating an indirect prompt injection surface. The risk is mitigated by the skill's specific grounding purpose and its explicit instructions for PII pseudonymization using the
let-it-betool.
Audit Metadata