skills/tinh2/skills-hub-registry/gdpr/Gen Agent Trust Hub

gdpr

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates privacy audits through static analysis, scanning data models and API endpoints to identify PII fields and collection points.
  • [SAFE]: A telemetry logging mechanism is included that appends metadata about the execution (such as date, outcome, and bottlenecks) to a local file in ~/.claude/projects/. This is used for internal skill performance tracking and does not involve network exfiltration or unauthorized persistence.
  • [SAFE]: The instructions include robust safety guardrails, explicitly prohibiting the agent from modifying code, providing legal advice, or exposing actual PII values in the generated reports.
  • [PROMPT_INJECTION]: The skill processes untrusted codebase data provided via arguments. This creates a surface for indirect prompt injection where instructions embedded in the scanned code could attempt to influence the agent. However, the risk is minimal as the skill is restricted to read-only assessment and has explicit instructions to ignore such prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — gdpr