aia-generation
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill accesses configuration and matter files stored within its designated workspace at
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/. These operations are limited to the plugin's own data management. - [DATA_EXFILTRATION]: The skill communicates with well-known legal research platforms (e.g., Westlaw, EUR-Lex) to identify regulatory classifications and obligations, representing standard functionality for legal analysis tools.
- [PROMPT_INJECTION]: The skill handles untrusted user input describing AI systems (Ingestion points: Step 2 Intake in SKILL.md). Although it lacks sanitization and boundary markers, the risk of indirect prompt injection is mitigated by the skill's restricted file-system scope and the requirement for human verification of all AI-generated citations and a final sign-off gate.
Audit Metadata