aia-generation

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill accesses configuration and matter files stored within its designated workspace at ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/. These operations are limited to the plugin's own data management.
  • [DATA_EXFILTRATION]: The skill communicates with well-known legal research platforms (e.g., Westlaw, EUR-Lex) to identify regulatory classifications and obligations, representing standard functionality for legal analysis tools.
  • [PROMPT_INJECTION]: The skill handles untrusted user input describing AI systems (Ingestion points: Step 2 Intake in SKILL.md). Although it lacks sanitization and boundary markers, the risk of indirect prompt injection is mitigated by the skill's restricted file-system scope and the requirement for human verification of all AI-generated citations and a final sign-off gate.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — aia-generation