Data-Minimization / Purpose-Limitation Check
The privacy failure that fires even with zero secret and zero unauthorized sink.
Every exfil / egress / data-flow scorer grades the UNAUTHORIZED movement of a CANARY or SECRET. NOTHING grades DATA MINIMIZATION / PURPOSE LIMITATION — whether an agent, across a run, COLLECTS, PROPAGATES, RETAINS, or TRANSMITS MORE personal-data categories than its DECLARED PURPOSE requires (GDPR Art.5(1)(b) purpose limitation + (1)(c) minimization, Art.9 special-category, CCPA, NIST AI RMF privacy). It is complementary, not overlapping, with the secret-exfil scorers: a leak scorer fires only when a SECRET reaches an UNAUTHORIZED sink; AgentSmack fires here when LAWFUL data is over-collected, retained-too-long, or used-beyond-its-stated-purpose even with zero secret and zero unauthorized sink. Declare a purpose (allowed data classes · allowed recipients · retention), then score a transcript for over-collection, special-category over-collection, unauthorized-recipient disclosure, and over-retention — surfaced as a per-event timeline, mapped to OWASP LLM / NIST AI RMF coverage with paste-able remediation, a synthetic-attacker gauntlet, and audience report variants. A data.minimized for a class before its use clears the heuristic; no declared purpose returns honest-empty. Load a sample to watch the gauge swing with no live infra.