bar-prep-questions
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches authoritative exam information and subject outlines from the National Conference of Bar Examiners (NCBE) official website (ncbex.org).
- [PROMPT_INJECTION]: The skill processes user-specific data from configuration files and essays to customize questions, representing a standard indirect prompt injection surface.
- Ingestion points: Loads bar jurisdiction and weak subjects from
~/.claude/plugins/config/claude-for-legal/law-student/CLAUDE.mdandstudy-plan.yaml. - Boundary markers: No explicit delimiters are used to wrap ingested file content.
- Capability inventory: The skill is restricted to text generation and writing to local history files; it lacks shell command execution or network exfiltration capabilities.
- Sanitization: No explicit validation or escaping is performed on the ingested metadata or user essays.
Audit Metadata