legal-cog

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill description contains deceptive performance claims designed to influence user and agent perception of its capabilities.
  • Evidence: The description and body text claim the skill is "#1 on DeepResearch Bench (Feb 2026)", which refers to a future date relative to current standards, indicating fabricated or misleading performance metrics.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a documentation layer for an agent that processes untrusted natural language input to generate high-stakes legal documents, creating an injection surface.
  • Ingestion points: User-supplied deal terms, party names, and jurisdictional requirements provided in the prompt field of the create_chat function.
  • Boundary markers: The skill instructions do not define delimiters or specific "ignore" instructions for the agent when processing user inputs.
  • Capability inventory: The skill utilizes the cellcog SDK to generate PDF documents and execute API-based reasoning tasks.
  • Sanitization: No sanitization or validation protocols are described to verify the integrity of user-provided prompt data before it is processed by the underlying model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:33 PM
Security Audit — agent-trust-hub — legal-cog