rgpd-request

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized network operations were detected. The skill uses standard markdown templates to assist the user.- [DATA_EXFILTRATION]: The skill processes user-provided information (name, email) to fill placeholders in GDPR request templates. This data is provided by the user for the explicit purpose of generating the request and is not sent to unauthorized third parties.- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface by instructing the agent to read external web pages (Privacy Policies) to find contact information. ● Ingestion points: External website content during DPO contact search (SKILL.md). ● Boundary markers: Absent. ● Capability inventory: Text generation and web searching. No dangerous system capabilities (exec/eval/file-write) are present. ● Sanitization: Absent. While a surface exists, the limited capabilities of the skill and its focus on generating draft emails render the risk negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 05:15 PM