contract-risk-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted text from user-provided contracts and SOWs. This creates an attack surface, but the risk is mitigated as the skill lacks any capabilities to execute code, access the network, or write files.
- Ingestion points: User-provided legal documents (MSA, SOW, NDA) processed via the analysis instructions in
SKILL.md. - Boundary markers: None identified in the prompt instructions to delimit untrusted content.
- Capability inventory: No subprocess calls, network operations, file-write capabilities, or tool usage are present in the skill.
- Sanitization: No explicit sanitization or filtering of input text is defined.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected in the skill instructions or reference files. The templates and checklists provided are standard business tools.
Audit Metadata