Back to skill

Security audit

Data Privacy Law Explainer

Security checks for vulnerabilities and agentic risk

Overview

This is an offline legal-information skill with scoped state privacy-law notes; the scanner alerts are mostly legal text misread as commands, with only an optional unpinned npx install suggestion worth caution.

Safe to install as a legal-information reference, but do not treat its answers as legal advice and verify current law before relying on it. Avoid running the optional `npx skills add open-agreements/open-agreements` command unless you separately trust and review the package/repository or can pin it to a reviewed version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:103
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:103
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: Medium

Vulnerable Code Snippet:

markdown
(install: `npx skills add open-agreements/open-agreements`).

Technical Analysis

The skill recommends invoking the skills npm package through npx without specifying a reviewed version or validating package integrity. If the package is not already installed, npx may download and execute the version currently published in the configured npm registry.

Because package resolution is mutable, the code executed when a user follows this instruction may differ from the code available when the skill was audited. The target repository is likewise not pinned to an immutable commit in this command. A compromised npm account, malicious package update, dependency compromise, registry substitution, or unexpected upstream change could therefore introduce arbitrary installer behavior.

The command is presented as an optional installation recommendation and is not automatically executed by this skill. Exploitation consequently requires a user or agent to follow the recommendation.

Attack Path

  1. An attacker compromises the resolved skills npm package, one of its executable dependencies, or the repository content retrieved by the installer.
  2. The attacker publishes malicious code under the mutable package or repository reference.
  3. A user or agent follows the recommendation in SKILL.md and runs:
    shell
    npx skills add open-agreements/open-agreements
    
  4. npx resolves and downloads the current package version from the configured registry.
  5. The downloaded package executes with the privileges and environment of the invoking user.
  6. Malicious installer logic can access resources available to that user and may install additional unreviewed content.

Impact Assessment

Successful exploitation co ...[truncated 615 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the executable installation command from the legal-information skill unless it is essential to the skill's primary purpose.
  2. If installation guidance must remain, pin the CLI to a specifically reviewed version rather than relying on mutable resolution, for example:
    shell
    npx --yes skills@<reviewed-version> add open-agreements/open-agreements
    
  3. Pin the installed repository or package content to an immutable release or commit where the installer supports it.
  4. Verify package integrity through an approved lockfile, cryptographic digest, signed release, or trusted internal registry.
  5. Require explicit, informed user approval immediately before executing any package-manager command. The agent must not run the command automatically.
  6. Execute installation in a sandbox with minimal filesystem, credential, and network access.
  7. Review the CLI package, its transitive dependencies, and the exact target revision before recommending or executing the installation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (44)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · content/massachusetts.md (reported line 116)May include surrounding context.

md
> [!NOTE]
> **Practice note.**
>
> Treat chat widgets, support messaging, and any tool that records the contents of customer conversations as the highest-risk tracking surface in Massachusetts. Browsing-activity analytics fell out of the wiretap act in 2024, but the statute still prohibits secretly recording the contents of wire or oral communications without all-party authority [^q7-9999-interception], and its civil remedy carries a $1,000 minimum per aggrieved person plus punitive damages and fees [^q7-9999-remedy]. Obtain clear consent before any communication-content capture runs, and expect c. 93A § 9 demand letters as the routine opening move in tracking disputes [^q7-93a9-demand].

## How is privacy law enforced in Massachusetts? {#ag-enforcement}

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · content/massachusetts.md (reported line 240)May include surrounding context.

md
> [!NOTE]
> **Practice note.**
>
> Treat chat widgets, support messaging, and any tool that records the contents of customer conversations as the highest-risk tracking surface in Massachusetts. Browsing-activity analytics fell out of the wiretap act in 2024, but the statute still prohibits secretly recording the contents of wire or oral communications without all-party authority [^q7-9999-interception], and its civil remedy carries a $1,000 minimum per aggrieved person plus punitive damages and fees [^q7-9999-remedy]. Obtain clear consent before any communication-content capture runs, and expect c. 93A § 9 demand letters as the routine opening move in tracking disputes [^q7-93a9-demand].

## How is privacy law enforced in Massachusetts? {#ag-enforcement}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · content/new-mexico.md (reported line 78)May include surrounding context.

md
**Short answer.** A person that owns or licenses personal identifying information of New Mexico residents must notify each resident whose information is reasonably believed to have been subject to a security breach — in the most expedient time possible and no later than 45 calendar days after discovery [^q5-dbna-notice-duty]. Notice is excused if an appropriate investigation determines the breach does not give rise to a significant risk of identity theft or fraud [^q5-dbna-risk-of-harm]. If a single breach requires notice to more than 1,000 New Mexico residents, you must also notify the office of the attorney general and the nationwide consumer reporting agencies on the same 45-day clock [^q5-dbna-ag-cra]. And a vendor holding data it does not own owes the data's owner notice of any breach within the same 45 days [^q5-dbna-maintainer-notice].

Start with what counts. A *security breach* is the unauthorized acquisition of unencrypted computerized data — or of encrypted data together with the key — that compromises personal identifying information; a good-faith acquisition by an employee or agent for a legitimate business purpose is carved out, so long as the information goes no further [^q5-dbna-breach-def]. The trigger is acquisition, not mere access, and it reaches only computerized data — a lost box of paper files does not start the notice clock. *Personal identifying information* means a resident's name combined with an unprotected Social Security number, driver's license number, government-issued ID number, financial-account or card number with its access credentials, or biometric data — and excludes information lawfully available from public sources [^q5-dbna-pii-def]. Encryption and redaction are built-in safe harbors: data elements that are encrypted or otherwise rendered unusable fall outside the definition unless the decryption key was compromised too.

The notice itself has statutorily fixed contents — your name and contact information, the types of inform
...[truncated 26 chars]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · content/south-dakota.md (reported line 79)May include surrounding context.

md
**Short answer.** Within sixty days. After discovering or being notified of a breach of system security, an information holder must disclose the breach to any South Dakota resident whose personal or protected information was, or is reasonably believed to have been, acquired by an unauthorized person, not later than sixty days from discovery, unless law enforcement needs a delay [^q5-notice-duty]. If the breach exceeds two hundred fifty residents, the information holder must also disclose it to the attorney general [^q5-ag-threshold], and any breach requiring resident notice triggers notice to the nationwide consumer reporting agencies without unreasonable delay [^q5-cra-notice].

The trigger is the unauthorized acquisition of unencrypted computerized data — or encrypted data together with the encryption key — that materially compromises personal or protected information [^q5-trigger]. South Dakota uses a distinctive two-tier data definition. *Personal information* is name-keyed: a name plus a Social Security number, government-issued ID number, financial-account access combination, health information, or an employer ID with an access credential. *Protected information* needs no name at all — a username or email address combined with a password or security-question answer, or a financial-account number with its access code, is enough on its own [^q5-protected-info]. A credential-stuffing incident can therefore be reportable in South Dakota even where a name-keyed statute would not reach it.

Notice may be written or electronic, with substitute notice (email plus website posting plus statewide media) available where the cost would exceed two hundred fifty thousand dollars, the affected class exceeds five hundred thousand persons, or contact information is insufficient [^q5-methods]. An information holder may also follow its own notification procedure if that procedure is part of an information-security policy and is otherwise consistent with the statute's timing requi
...[truncated 25 chars]

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/alabama.md (reported line 91)May include surrounding context.

md
| **Summary** | If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired. |
| **Main law** | Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025 |
| **Privacy policy required?** | Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents |
| **Who does it cover?** | Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent |
| **Can consumers sue?** | No |
| **Privacy policy rule** | Policy contents fixed by law |
| **Consent for sensitive data?** | Consent required first |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/florida.md (reported line 49)May include surrounding context.

md
| **Summary** | If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired. |
| **Main law** | Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025 |
| **Privacy policy required?** | Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents |
| **Who does it cover?** | Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent |
| **Can consumers sue?** | No |
| **Privacy policy rule** | Policy contents fixed by law |
| **Consent for sensitive data?** | Consent required first |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/florida.md (reported line 55)May include surrounding context.

md
| **Summary** | If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired. |
| **Main law** | Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025 |
| **Privacy policy required?** | Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents |
| **Who does it cover?** | Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent |
| **Can consumers sue?** | No |
| **Privacy policy rule** | Policy contents fixed by law |
| **Consent for sensitive data?** | Consent required first |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/minnesota.md (reported line 33)May include surrounding context.

md
| **Summary** | If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired. |
| **Main law** | Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025 |
| **Privacy policy required?** | Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents |
| **Who does it cover?** | Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent |
| **Can consumers sue?** | No |
| **Privacy policy rule** | Policy contents fixed by law |
| **Consent for sensitive data?** | Consent required first |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/minnesota.md (reported line 63)May include surrounding context.

md
| **Summary** | If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired. |
| **Main law** | Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025 |
| **Privacy policy required?** | Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents |
| **Who does it cover?** | Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent |
| **Can consumers sue?** | No |
| **Privacy policy rule** | Policy contents fixed by law |
| **Consent for sensitive data?** | Consent required first |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/new-jersey.md (reported line 63)May include surrounding context.

md
| **Summary** | If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired. |
| **Main law** | Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025 |
| **Privacy policy required?** | Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents |
| **Who does it cover?** | Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent |
| **Can consumers sue?** | No |
| **Privacy policy rule** | Policy contents fixed by law |
| **Consent for sensitive data?** | Consent required first |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/oklahoma.md (reported line 70)May include surrounding context.

md
| **Summary** | If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired. |
| **Main law** | Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025 |
| **Privacy policy required?** | Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents |
| **Who does it cover?** | Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent |
| **Can consumers sue?** | No |
| **Privacy policy rule** | Policy contents fixed by law |
| **Consent for sensitive data?** | Consent required first |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/oklahoma.md (reported line 72)May include surrounding context.

md
| **Summary** | If you control or process the data of 100,000+ Minnesota consumers (or 25,000+ plus over 25% of revenue from data sales), the MCDPA requires a privacy notice, opt-in consent to process sensitive data, and processor contracts — plus a uniquely strict list-of-third-parties right and profiling-reevaluation rights. The Attorney General enforces it; there are no consumer lawsuits, and the 30-day cure period has already expired. |
| **Main law** | Minn. Stat. §§ 325M.10–325M.21 (Minnesota Consumer Data Privacy Act), effective July 31, 2025 |
| **Privacy policy required?** | Yes — a reasonably accessible, clear, and meaningful notice with statutorily fixed contents |
| **Who does it cover?** | Legal entities doing business in Minnesota (or targeting residents) that control or process the data of 100,000+ consumers a year (excluding payment-only data), or 25,000+ while deriving over 25% of gross revenue from selling data — no general nonprofit exemption; small businesses exempt except they still cannot sell sensitive data without consent |
| **Can consumers sue?** | No |
| **Privacy policy rule** | Policy contents fixed by law |
| **Consent for sensitive data?** | Consent required first |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/illinois.md (reported line 73)May include surrounding context.

md
## What does South Carolina's minors' design code require your service to do? {#minors-law-duties}

**Short answer.** The core obligation is a duty of reasonable care: a covered online service must exercise reasonable care in its use of a minor's personal data and in the design and operation of the service to prevent enumerated harms to minors, from compulsive usage and severe psychological harm to identity theft and financial or physical injury [^q3-act96-reasonable-care]. That design duty reaches *covered design features* such as infinite scroll, autoplay, gamification, engagement counts, push alerts, in-game purchases, and appearance-altering filters [^q3-act96-design-features]. Around that duty the act layers hard data rules: a service may collect, use, or share only the minimum amount of a minor's personal data necessary for the parts of the service the minor knowingly engages with, and age-verification data must be deleted after use [^q3-act96-minimization]; targeted advertising to minors is flatly banned, with no consent path [^q3-act96-targeted-ads]; and the protections in that section must be set at the highest level by default [^q3-act96-defaults].

The act is as much a product-design mandate as a data statute. Every user — not just known minors — must get easily accessible tools to disable covered design features that are not necessary to the service and to limit time spent on it [^q3-act96-user-tools]. Users must be offered an opt-out from personalized recommendation systems, and that opt-out must be the default setting for any individual the service knows to be a minor [^q3-act96-recsys-default]. Parents must get accessible tools — on by default for known minors — to manage the minor's settings, restrict purchases, view time spent, and set time-of-day limits, with notice to the minor when those tools are active [^q3-act96-parental-tools]. Precise-geolocation collection defaults off, notification-curfew tools must cover overnight and school hours, and pa
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/nevada.md (reported line 75)May include surrounding context.

md
## What does South Carolina's minors' design code require your service to do? {#minors-law-duties}

**Short answer.** The core obligation is a duty of reasonable care: a covered online service must exercise reasonable care in its use of a minor's personal data and in the design and operation of the service to prevent enumerated harms to minors, from compulsive usage and severe psychological harm to identity theft and financial or physical injury [^q3-act96-reasonable-care]. That design duty reaches *covered design features* such as infinite scroll, autoplay, gamification, engagement counts, push alerts, in-game purchases, and appearance-altering filters [^q3-act96-design-features]. Around that duty the act layers hard data rules: a service may collect, use, or share only the minimum amount of a minor's personal data necessary for the parts of the service the minor knowingly engages with, and age-verification data must be deleted after use [^q3-act96-minimization]; targeted advertising to minors is flatly banned, with no consent path [^q3-act96-targeted-ads]; and the protections in that section must be set at the highest level by default [^q3-act96-defaults].

The act is as much a product-design mandate as a data statute. Every user — not just known minors — must get easily accessible tools to disable covered design features that are not necessary to the service and to limit time spent on it [^q3-act96-user-tools]. Users must be offered an opt-out from personalized recommendation systems, and that opt-out must be the default setting for any individual the service knows to be a minor [^q3-act96-recsys-default]. Parents must get accessible tools — on by default for known minors — to manage the minor's settings, restrict purchases, view time spent, and set time-of-day limits, with notice to the minor when those tools are active [^q3-act96-parental-tools]. Precise-geolocation collection defaults off, notification-curfew tools must cover overnight and school hours, and pa
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/south-carolina.md (reported line 55)May include surrounding context.

md
## What does South Carolina's minors' design code require your service to do? {#minors-law-duties}

**Short answer.** The core obligation is a duty of reasonable care: a covered online service must exercise reasonable care in its use of a minor's personal data and in the design and operation of the service to prevent enumerated harms to minors, from compulsive usage and severe psychological harm to identity theft and financial or physical injury [^q3-act96-reasonable-care]. That design duty reaches *covered design features* such as infinite scroll, autoplay, gamification, engagement counts, push alerts, in-game purchases, and appearance-altering filters [^q3-act96-design-features]. Around that duty the act layers hard data rules: a service may collect, use, or share only the minimum amount of a minor's personal data necessary for the parts of the service the minor knowingly engages with, and age-verification data must be deleted after use [^q3-act96-minimization]; targeted advertising to minors is flatly banned, with no consent path [^q3-act96-targeted-ads]; and the protections in that section must be set at the highest level by default [^q3-act96-defaults].

The act is as much a product-design mandate as a data statute. Every user — not just known minors — must get easily accessible tools to disable covered design features that are not necessary to the service and to limit time spent on it [^q3-act96-user-tools]. Users must be offered an opt-out from personalized recommendation systems, and that opt-out must be the default setting for any individual the service knows to be a minor [^q3-act96-recsys-default]. Parents must get accessible tools — on by default for known minors — to manage the minor's settings, restrict purchases, view time spent, and set time-of-day limits, with notice to the minor when those tools are active [^q3-act96-parental-tools]. Precise-geolocation collection defaults off, notification-curfew tools must cover overnight and school hours, and pa
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/washington.md (reported line 95)May include surrounding context.

md
## What does South Carolina's minors' design code require your service to do? {#minors-law-duties}

**Short answer.** The core obligation is a duty of reasonable care: a covered online service must exercise reasonable care in its use of a minor's personal data and in the design and operation of the service to prevent enumerated harms to minors, from compulsive usage and severe psychological harm to identity theft and financial or physical injury [^q3-act96-reasonable-care]. That design duty reaches *covered design features* such as infinite scroll, autoplay, gamification, engagement counts, push alerts, in-game purchases, and appearance-altering filters [^q3-act96-design-features]. Around that duty the act layers hard data rules: a service may collect, use, or share only the minimum amount of a minor's personal data necessary for the parts of the service the minor knowingly engages with, and age-verification data must be deleted after use [^q3-act96-minimization]; targeted advertising to minors is flatly banned, with no consent path [^q3-act96-targeted-ads]; and the protections in that section must be set at the highest level by default [^q3-act96-defaults].

The act is as much a product-design mandate as a data statute. Every user — not just known minors — must get easily accessible tools to disable covered design features that are not necessary to the service and to limit time spent on it [^q3-act96-user-tools]. Users must be offered an opt-out from personalized recommendation systems, and that opt-out must be the default setting for any individual the service knows to be a minor [^q3-act96-recsys-default]. Parents must get accessible tools — on by default for known minors — to manage the minor's settings, restrict purchases, view time spent, and set time-of-day limits, with notice to the minor when those tools are active [^q3-act96-parental-tools]. Precise-geolocation collection defaults off, notification-curfew tools must cover overnight and school hours, and pa
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · content/washington.md (reported line 97)May include surrounding context.

md
## What does South Carolina's minors' design code require your service to do? {#minors-law-duties}

**Short answer.** The core obligation is a duty of reasonable care: a covered online service must exercise reasonable care in its use of a minor's personal data and in the design and operation of the service to prevent enumerated harms to minors, from compulsive usage and severe psychological harm to identity theft and financial or physical injury [^q3-act96-reasonable-care]. That design duty reaches *covered design features* such as infinite scroll, autoplay, gamification, engagement counts, push alerts, in-game purchases, and appearance-altering filters [^q3-act96-design-features]. Around that duty the act layers hard data rules: a service may collect, use, or share only the minimum amount of a minor's personal data necessary for the parts of the service the minor knowingly engages with, and age-verification data must be deleted after use [^q3-act96-minimization]; targeted advertising to minors is flatly banned, with no consent path [^q3-act96-targeted-ads]; and the protections in that section must be set at the highest level by default [^q3-act96-defaults].

The act is as much a product-design mandate as a data statute. Every user — not just known minors — must get easily accessible tools to disable covered design features that are not necessary to the service and to limit time spent on it [^q3-act96-user-tools]. Users must be offered an opt-out from personalized recommendation systems, and that opt-out must be the default setting for any individual the service knows to be a minor [^q3-act96-recsys-default]. Parents must get accessible tools — on by default for known minors — to manage the minor's settings, restrict purchases, view time spent, and set time-of-day limits, with notice to the minor when those tools are active [^q3-act96-parental-tools]. Precise-geolocation collection defaults off, notification-curfew tools must cover overnight and school hours, and pa
...[truncated 25 chars]

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The invocation description includes generic phrases such as "privacy policy" and "state privacy law," which can apply to many privacy, security, or legal tasks outside U.S. state consumer-privacy law explainers. The trigger guidance does not include negative examples or constraints clarifying when the skill should not activate, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · content/alabama.md (reported line 169)May include surrounding context.

md
## Can your business sell sensitive data in Florida without consent? {#sensitive-data-sale}

**Short answer.** No — and unlike the rest of the FDBR, this rule is not limited to billion-dollar controllers. Section 501.715 reaches any person meeting only the first three elements of the controller definition — a for-profit entity that conducts business in Florida and collects consumers' personal data (or has it collected on its behalf) — and bars it from selling sensitive data without prior consumer consent, with COPPA-tier rules for known children [^q2-sale-rule]. A seller of sensitive data must also post the statute's scripted notice, word for word: "NOTICE: This website may sell your sensitive personal data."[^q2-sale-rule] [^q2-sale-rule]

The reach of this rule turns on how broadly Florida defines *sensitive data*: data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to identify a person; all personal data collected from a known child — meaning anyone under 18 in Florida, not under 13; and precise geolocation data [^q2-sensitive-def]. An ordinary app publisher or retailer that monetizes location data or under-18 user data for monetary or other valuable consideration can therefore sit squarely inside an FDBR provision even though it fails the $1 billion test [^q2-sale-def]. The part-wide entity exemptions (GLBA financial institutions, HIPAA covered entities, nonprofits) still apply [^q2-fdbr-exemptions], and the *sale* definition excludes disclosures to processors and disclosures for a product or service requested by the consumer [^q2-sale-def]. No Florida decision or Attorney General guidance has yet construed how far § 501.715 extends in practice, so the conservative reading — any for-profit Florida business selling sensitive data needs prior consent and the posted notice — is the safer planning assumption.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · content/arkansas.md (reported line 217)May include surrounding context.

md
## Can your business sell sensitive data in Florida without consent? {#sensitive-data-sale}

**Short answer.** No — and unlike the rest of the FDBR, this rule is not limited to billion-dollar controllers. Section 501.715 reaches any person meeting only the first three elements of the controller definition — a for-profit entity that conducts business in Florida and collects consumers' personal data (or has it collected on its behalf) — and bars it from selling sensitive data without prior consumer consent, with COPPA-tier rules for known children [^q2-sale-rule]. A seller of sensitive data must also post the statute's scripted notice, word for word: "NOTICE: This website may sell your sensitive personal data."[^q2-sale-rule] [^q2-sale-rule]

The reach of this rule turns on how broadly Florida defines *sensitive data*: data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to identify a person; all personal data collected from a known child — meaning anyone under 18 in Florida, not under 13; and precise geolocation data [^q2-sensitive-def]. An ordinary app publisher or retailer that monetizes location data or under-18 user data for monetary or other valuable consideration can therefore sit squarely inside an FDBR provision even though it fails the $1 billion test [^q2-sale-def]. The part-wide entity exemptions (GLBA financial institutions, HIPAA covered entities, nonprofits) still apply [^q2-fdbr-exemptions], and the *sale* definition excludes disclosures to processors and disclosures for a product or service requested by the consumer [^q2-sale-def]. No Florida decision or Attorney General guidance has yet construed how far § 501.715 extends in practice, so the conservative reading — any for-profit Florida business selling sensitive data needs prior consent and the posted notice — is the safer planning assumption.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · content/florida.md (reported line 51)May include surrounding context.

md
## Can your business sell sensitive data in Florida without consent? {#sensitive-data-sale}

**Short answer.** No — and unlike the rest of the FDBR, this rule is not limited to billion-dollar controllers. Section 501.715 reaches any person meeting only the first three elements of the controller definition — a for-profit entity that conducts business in Florida and collects consumers' personal data (or has it collected on its behalf) — and bars it from selling sensitive data without prior consumer consent, with COPPA-tier rules for known children [^q2-sale-rule]. A seller of sensitive data must also post the statute's scripted notice, word for word: "NOTICE: This website may sell your sensitive personal data."[^q2-sale-rule] [^q2-sale-rule]

The reach of this rule turns on how broadly Florida defines *sensitive data*: data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to identify a person; all personal data collected from a known child — meaning anyone under 18 in Florida, not under 13; and precise geolocation data [^q2-sensitive-def]. An ordinary app publisher or retailer that monetizes location data or under-18 user data for monetary or other valuable consideration can therefore sit squarely inside an FDBR provision even though it fails the $1 billion test [^q2-sale-def]. The part-wide entity exemptions (GLBA financial institutions, HIPAA covered entities, nonprofits) still apply [^q2-fdbr-exemptions], and the *sale* definition excludes disclosures to processors and disclosures for a product or service requested by the consumer [^q2-sale-def]. No Florida decision or Attorney General guidance has yet construed how far § 501.715 extends in practice, so the conservative reading — any for-profit Florida business selling sensitive data needs prior consent and the posted notice — is the safer planning assumption.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · content/illinois.md (reported line 146)May include surrounding context.

md
## Can your business sell sensitive data in Florida without consent? {#sensitive-data-sale}

**Short answer.** No — and unlike the rest of the FDBR, this rule is not limited to billion-dollar controllers. Section 501.715 reaches any person meeting only the first three elements of the controller definition — a for-profit entity that conducts business in Florida and collects consumers' personal data (or has it collected on its behalf) — and bars it from selling sensitive data without prior consumer consent, with COPPA-tier rules for known children [^q2-sale-rule]. A seller of sensitive data must also post the statute's scripted notice, word for word: "NOTICE: This website may sell your sensitive personal data."[^q2-sale-rule] [^q2-sale-rule]

The reach of this rule turns on how broadly Florida defines *sensitive data*: data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to identify a person; all personal data collected from a known child — meaning anyone under 18 in Florida, not under 13; and precise geolocation data [^q2-sensitive-def]. An ordinary app publisher or retailer that monetizes location data or under-18 user data for monetary or other valuable consideration can therefore sit squarely inside an FDBR provision even though it fails the $1 billion test [^q2-sale-def]. The part-wide entity exemptions (GLBA financial institutions, HIPAA covered entities, nonprofits) still apply [^q2-fdbr-exemptions], and the *sale* definition excludes disclosures to processors and disclosures for a product or service requested by the consumer [^q2-sale-def]. No Florida decision or Attorney General guidance has yet construed how far § 501.715 extends in practice, so the conservative reading — any for-profit Florida business selling sensitive data needs prior consent and the posted notice — is the safer planning assumption.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · content/illinois.md (reported line 154)May include surrounding context.

md
## Can your business sell sensitive data in Florida without consent? {#sensitive-data-sale}

**Short answer.** No — and unlike the rest of the FDBR, this rule is not limited to billion-dollar controllers. Section 501.715 reaches any person meeting only the first three elements of the controller definition — a for-profit entity that conducts business in Florida and collects consumers' personal data (or has it collected on its behalf) — and bars it from selling sensitive data without prior consumer consent, with COPPA-tier rules for known children [^q2-sale-rule]. A seller of sensitive data must also post the statute's scripted notice, word for word: "NOTICE: This website may sell your sensitive personal data."[^q2-sale-rule] [^q2-sale-rule]

The reach of this rule turns on how broadly Florida defines *sensitive data*: data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to identify a person; all personal data collected from a known child — meaning anyone under 18 in Florida, not under 13; and precise geolocation data [^q2-sensitive-def]. An ordinary app publisher or retailer that monetizes location data or under-18 user data for monetary or other valuable consideration can therefore sit squarely inside an FDBR provision even though it fails the $1 billion test [^q2-sale-def]. The part-wide entity exemptions (GLBA financial institutions, HIPAA covered entities, nonprofits) still apply [^q2-fdbr-exemptions], and the *sale* definition excludes disclosures to processors and disclosures for a product or service requested by the consumer [^q2-sale-def]. No Florida decision or Attorney General guidance has yet construed how far § 501.715 extends in practice, so the conservative reading — any for-profit Florida business selling sensitive data needs prior consent and the posted notice — is the safer planning assumption.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · content/massachusetts.md (reported line 190)May include surrounding context.

md
## Can your business sell sensitive data in Florida without consent? {#sensitive-data-sale}

**Short answer.** No — and unlike the rest of the FDBR, this rule is not limited to billion-dollar controllers. Section 501.715 reaches any person meeting only the first three elements of the controller definition — a for-profit entity that conducts business in Florida and collects consumers' personal data (or has it collected on its behalf) — and bars it from selling sensitive data without prior consumer consent, with COPPA-tier rules for known children [^q2-sale-rule]. A seller of sensitive data must also post the statute's scripted notice, word for word: "NOTICE: This website may sell your sensitive personal data."[^q2-sale-rule] [^q2-sale-rule]

The reach of this rule turns on how broadly Florida defines *sensitive data*: data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to identify a person; all personal data collected from a known child — meaning anyone under 18 in Florida, not under 13; and precise geolocation data [^q2-sensitive-def]. An ordinary app publisher or retailer that monetizes location data or under-18 user data for monetary or other valuable consideration can therefore sit squarely inside an FDBR provision even though it fails the $1 billion test [^q2-sale-def]. The part-wide entity exemptions (GLBA financial institutions, HIPAA covered entities, nonprofits) still apply [^q2-fdbr-exemptions], and the *sale* definition excludes disclosures to processors and disclosures for a product or service requested by the consumer [^q2-sale-def]. No Florida decision or Attorney General guidance has yet construed how far § 501.715 extends in practice, so the conservative reading — any for-profit Florida business selling sensitive data needs prior consent and the posted notice — is the safer planning assumption.

Static analysis

No suspicious patterns detected.