bar-prep-questions

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches authoritative exam information and subject outlines from the National Conference of Bar Examiners (NCBE) official website (ncbex.org).
  • [PROMPT_INJECTION]: The skill processes user-specific data from configuration files and essays to customize questions, representing a standard indirect prompt injection surface.
  • Ingestion points: Loads bar jurisdiction and weak subjects from ~/.claude/plugins/config/claude-for-legal/law-student/CLAUDE.md and study-plan.yaml.
  • Boundary markers: No explicit delimiters are used to wrap ingested file content.
  • Capability inventory: The skill is restricted to text generation and writing to local history files; it lacks shell command execution or network exfiltration capabilities.
  • Sanitization: No explicit validation or escaping is performed on the ingested metadata or user essays.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — bar-prep-questions