uodo-grounding-pl

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Node.js runtime to execute a shared verification engine (ground-citations.mjs) located in a companion skill folder. This is a legitimate architectural pattern for code reuse across legal grounding tools.
  • [EXTERNAL_DOWNLOADS]: The skill performs targeted network requests to uodo.gov.pl and official EU legal databases via WebFetch to retrieve decision texts. These operations are performed on well-known government services and are necessary for the skill's primary function.
  • [PROMPT_INJECTION]: The skill ingests external content from official websites and user-provided documents, creating an indirect prompt injection surface. The risk is mitigated by the skill's specific grounding purpose and its explicit instructions for PII pseudonymization using the let-it-be tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 08:28 AM
Security Audit — agent-trust-hub — uodo-grounding-pl