Back to skill

Security audit

GDPR Guardrail

Security checks across malware telemetry and agentic risk

Overview

This is a local PII guardrail with no network or persistence, but its documented rule scope is imprecise and may cause false positives.

Before using this in enforcement mode, review and tune the rule pack for your jurisdiction and workflow. Start with detect or mask mode, because regex and keyword matching can produce false positives, especially the generic 10-digit NHS rule and copied examples that do not match the stated GDPR scope. Do not rely on it as legal advice or a complete compliance control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding
The documented scope promises an EU/GDPR-focused local guardrail, but the implementation description reportedly includes support for unrelated or overly broad identifier detection such as Chinese national ID logic and weak NHS-number matching. This mismatch is dangerous because operators may rely on the stated narrow scope and precision guarantees while the tool processes additional sensitive data classes or generates false positives/incorrect blocking decisions, undermining privacy controls and compliance expectations.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.