policy-drafting
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFE
Full Analysis
- Local File Access: The skill reads from and writes to
~/.claude/plugins/config/claude-for-legal/employment-legal/. This is used to maintain jurisdictional footprints and store drafted policies within matter-specific folders. This behavior is consistent with the skill's purpose as a legal drafting tool. - Indirect Prompt Injection Surface: The skill ingests data from local configuration files (
CLAUDE.md,matter.md). While these files are local, they represent a surface where external data enters the agent's context. The skill processes this information to customize policy drafts according to the user's jurisdictional footprint and specific legal matters.
Audit Metadata