Back to skill

Security audit

Cb Data Privacy Readiness Guide

Security checks for vulnerabilities and agentic risk

Overview

This is a descriptive privacy-readiness guide with no code execution or external access, but users should treat its compliance examples as planning prompts rather than legal conclusions.

Install only if you want a planning checklist for privacy readiness. Do not rely on its GDPR, CCPA, LGPD, PIPL, or other jurisdiction-specific statements as legal advice; have qualified privacy counsel verify compliance conclusions, thresholds, exemptions, data-transfer mechanisms, and templates before using them operationally.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill states it is only a descriptive readiness guide and not legal or compliance advice, but the examples make concrete compliance determinations, such as declaring data residency 'non-compliant' and asserting legal thresholds or exemptions. This can mislead users into relying on potentially inaccurate legal guidance without jurisdiction-specific review, creating regulatory and business risk.

Static analysis

No suspicious patterns detected.