client-letter
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Thorough analysis of the skill's instructions and script logic reveals no malicious patterns, unauthorized data access, or obfuscation.
- [PROMPT_INJECTION]: A potential surface for indirect prompt injection exists because the skill processes untrusted legal documents (Step 2 in SKILL.md). There are no explicit boundary markers or sanitization procedures. However, because the skill has no access to sensitive system tools, network operations, or file-writing capabilities, the technical impact of such an injection is restricted to generating incorrect text.
- [SAFE]: The skill contains built-in safety guidelines, referencing German legal standards (BORA, BRAO) to ensure the agent maintains client confidentiality and follows professional guidelines.
Audit Metadata