contract-risk-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted text from user-provided contracts and SOWs. This creates an attack surface, but the risk is mitigated as the skill lacks any capabilities to execute code, access the network, or write files.
  • Ingestion points: User-provided legal documents (MSA, SOW, NDA) processed via the analysis instructions in SKILL.md.
  • Boundary markers: None identified in the prompt instructions to delimit untrusted content.
  • Capability inventory: No subprocess calls, network operations, file-write capabilities, or tool usage are present in the skill.
  • Sanitization: No explicit sanitization or filtering of input text is defined.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected in the skill instructions or reference files. The templates and checklists provided are standard business tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — contract-risk-analyzer