cloak
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides comprehensive instructional content and reference documentation for privacy engineering and compliance. All code snippets included in the reference files, such as
references/implementation-patterns.md, are benign implementation examples for PII redaction, consent management, data subject access requests, and data retention enforcement.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to audit external codebases, logs, and database schemas, which serves as an ingestion point for untrusted data. This creates a potential attack surface for indirect prompt injection. However, the skill explicitly incorporates sanitization instructions, mandates the redaction of PII before output, and provides specific boundary instructions to mitigate these risks as part of its core functionality.
Audit Metadata