gdpr-dsgvo-expert

Warn

Audited by Runlayer on Feb 22, 2026

Risk Level: MEDIUM
Scan Summary
Max Score
78%
Files
7
Flagged
7
Chunks
14
Flagged Files (7)
SKILL.mdHIGH
78.3%

Malicious tool definition detected

Tool: SKILL.md [1/2] Description: --- name: gdpr-dsgvo-expert description: GDPR and German DSGVO compliance automation.

Tool: SKILL.md [2/2]

references/dpia_methodology.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/dpia_methodology.md [1/2] Description: # DPIA Methodology Data Protection Impact Assessment process, criteria, and checklists following GDPR Article 35 and WP29 guidelines. --- ## Table of Contents - [When DPIA is Required](#when-dpia-is-required) - [DPIA Process](#dpia-process) - [Risk Assessment](#risk-assessment) - [Consultation Requirements](#consultation-requirements) - [Templates and Checklists](#templates-and-checklists) --- ## When DPIA is Required ### Mandatory DPIA Tri

Tool: references/dpia_methodology.md [2/2] Description: - Confirm mitigation appropriateness - Document advice given **Step 6.3: Schedule Review** Review DPIA when: - Processing changes significantly - New risks emerge - Annually (minimum) - After incidents --- ## Risk Assessment ### Common Risks by Processing Type **Profiling and Automated Decisions:** - Discrimination - Inaccurate inferences - Lack of transparency - Denial of services **Large Scale Processing:** - Data breach impact - Difficul

references/gdpr_compliance_guide.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/gdpr_compliance_guide.md [1/2] Description: # GDPR Compliance Guide Practical implementation guidance for EU General Data Protection Regulation compliance. --- ## Table of Contents - [Legal Bases for Processing](#legal-bases-for-processing) - [Data Subject Rights](#data-subject-rights) - [Accountability Requirements](#accountability-requirements) - [International Transfers](#international-transfers) - [Breach Notification](#breach-notification) --- ## Legal Bases for Processing

Tool: references/gdpr_compliance_guide.md [2/2] Description: Module 1: Controller to Controller - Module 2: Controller to Processor - Module 3: Processor to Processor - Module 4: Processor to Controller **Implementation requirements:** 1.

references/german_bdsg_requirements.mdHIGH
78.3%

Malicious tool definition detected

Tool: references/german_bdsg_requirements.md [1/2] Description: # German BDSG Requirements German-specific data protection requirements under the Bundesdatenschutzgesetz (BDSG) and state laws.

Tool: references/german_bdsg_requirements.md [2/2] Description: for telecommunications and postal services - Representative in EDPB ### State Level Authorities **Competence:** - Private sector entities headquartered in the state - State public bodies ### Determining Competent Authority For private sector: 1.

scripts/data_subject_rights_tracker.pyHIGH
78.3%

Malicious tool definition detected

Tool: scripts/data_subject_rights_tracker.py [1/2] Description: #!/usr/bin/env python3 """ Data Subject Rights Tracker Tracks and manages data subject rights requests under GDPR Articles 15-22.

Tool: scripts/data_subject_rights_tracker.py [2/2] Description: "overdue_details": overdue, "performance": { "completed_on_time": completed_on_time, "completed_late": completed_late, "average_response_days": self._calculate_avg_response_time() } } def _calculate_avg_response_time(self) -> float: """Calculate average response time for completed requests.""" response_times = [] for req in self.requests["requests"]: if req["status"] == "completed" and req["dates"]["completed"]: received = datetime.

scripts/dpia_generator.pyHIGH
78.3%

Malicious tool definition detected

scripts/gdpr_compliance_checker.pyHIGH
78.3%

Malicious tool definition detected

Audit Metadata
Max File Score
78%
Classification
UNKNOWN_SERVER
Files Scanned
7
Files Flagged
7
Chunks Analyzed
14
Analyzed
Feb 22, 2026, 01:14 PM
Security Audit — runlayer — gdpr-dsgvo-expert