ai-data-privacy
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive, defensive instructions for security and privacy engineers to audit AI systems. It explicitly warns against unauthorized use and instructs the agent to act only as a reviewer, not an attacker.
- [COMMAND_EXECUTION]: The skill uses allowed tools (
Read,Grep,Glob) to search for common code patterns related to PII, datasets, and consent management. These patterns are standard for identification and do not involve executing suspicious shell commands or scripts. - [EXTERNAL_DOWNLOADS]: The skill references several well-known and trusted external resources for methodology and research, including NIST, OWASP, and academic papers from arXiv. All external links point to established, reputable domains (nist.gov, owasp.org, arxiv.org, microsoft.com). These references are used solely for educational and framework-alignment purposes.
- [PROMPT_INJECTION]: The skill includes a dedicated 'Prompt Injection Safety Notice' that instructs the agent to ignore any injection payloads found within the reviewed code and to flag them instead of following them. It also uses
$ARGUMENTSin a standard instructional context to scope the review. - [DATA_EXFILTRATION]: There are no indicators of data exfiltration. The skill focuses on detecting data exposure risks within the user's own environment (e.g., PII being sent to third-party APIs) and provides remediation guidance to prevent such exfiltration.
Audit Metadata