uodo-grounding-pl

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute a local Node.js script located at ../citation-grounding-pl/scripts/ground-citations.mjs. This script serves as a shared verification engine. The execution is scoped to a local directory and is necessary for the skill's mechanical grounding functionality.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from the official uodo.gov.pl website using WebFetch to confirm the existence and content of legal decisions. This is a trusted government domain, and the operation is consistent with the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes legal claims and citations which are external inputs. It mitigates the risk of processing sensitive or malicious data by recommending the use of the let-it-be skill for PII pseudonimization. Evidence Chain: (1) Ingestion points: User-provided legal claims and fetched decision texts mentioned in SKILL.md. (2) Boundary markers: The workflow involves structured JSON inputs for the verification script. (3) Capability inventory: Bash for command execution and WebFetch for remote data retrieval. (4) Sanitization: Explicit instruction to use let-it-be for privacy and safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:31 PM
Security Audit — agent-trust-hub — uodo-grounding-pl