ops-contract-review

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill functions as a text-based advisory tool for business contract review. It provides instructions to the agent on how to categorize and assess risks within legal agreements.
  • [NO_CODE]: No scripts (Python, JavaScript, Shell) or executable binaries are included in the skill package. The skill relies entirely on natural language instructions.
  • [DATA_EXPOSURE_EXFILTRATION]: No network operations, file system access, or hardcoded secrets were detected. The skill does not access sensitive local configuration files or environment variables.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data (contract text). While the input text could theoretically contain instructions designed to bypass the agent's logic, the skill provides a robust structured framework and an 'IRON LAW' that anchors the agent's behavior to a specific checklist, mitigating the risk of following embedded instructions. The skill has no capabilities to execute commands or reach the network, limiting the impact of any potential injection.
  • [OBFUSCATION]: No hidden characters, Base64 encoding, or homoglyph attacks were detected in the instructions or example files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:06 PM
Security Audit — agent-trust-hub — ops-contract-review