amendment-history
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data (contracts and amendments), which represents an indirect prompt injection surface.
- Ingestion points: Contract files uploaded by the user, pasted text, and planned integrations with CLM and document repositories (SKILL.md).
- Boundary markers: The instructions mandate using markdown headers and specific blockquotes (
> "[exact quote]") to separate contract content from agent analysis. - Capability inventory: The skill has file-read and file-write capabilities within the
~/.claude/plugins/config/claude-for-legal/directory (SKILL.md). - Sanitization: The skill relies on exact quoting and plain English summarization rather than formal sanitization or filtering of the ingested document text.
Audit Metadata