law-contract

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external text (contracts), which serves as an entry point for untrusted data.
  • Ingestion points: The skill processes user-supplied agreement text as specified in the SKILL.md instructions.
  • Boundary markers: The instructions do not include specific delimiters or warnings to ignore malicious instructions embedded within the analyzed contract text.
  • Capability inventory: No subprocess calls, network operations, or file-writing tools were detected within the skill's instructions or referenced files.
  • Sanitization: No input validation or sanitization of the contract text is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:05 PM
Security Audit — agent-trust-hub — law-contract