socratic-drill

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • Local File Access for Personalization: The skill is designed to load specific configuration data from ~/.claude/plugins/config/claude-for-legal/law-student/CLAUDE.md. This path appears to be dedicated to the skill's own configuration and learning style preferences. While it involves accessing the file system, it is restricted to its own plugin directory to provide a tailored user experience.
  • Indirect Prompt Injection Surface: The skill processes user-provided study materials (notes, outlines, case briefs) to identify contradictions. This is a core educational feature, though it conceptually introduces an entry point for external content. The skill mitigates risks by focusing on identifying specific substantive contradictions rather than executing instructions found within those materials.
  • Legal Advice Safety Guardrails: The skill explicitly includes a 'Real-matter check' designed to identify when a user is seeking actual legal advice rather than academic drilling. It instructs the agent to provide a disclaimer and redirect the user to professional legal services, which is a positive safety behavior for an educational tool in the legal domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 08:45 PM
Security Audit — agent-trust-hub — socratic-drill