brief-section-drafter
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses local configuration and log files located at
~/.claude/plugins/config/claude-for-legal/to retrieve case theory, firm styles, and matter logs. These accesses are scoped to the plugin's internal configuration and are used to enforce a 'conflicts gate' (verifying the matter is intaken before drafting). No network exfiltration of this data was detected. - [PROMPT_INJECTION]: The skill processes potentially untrusted external data, such as case chronologies and document sets, which presents a surface for indirect prompt injection. This risk is mitigated through robust instructional guardrails, including mandatory citation markers (
[VERIFY],[CITE NEEDED]), explicit warnings about Rule 11 sanctions, and strict requirements for human attorney review before any output is finalized or filed. - [EXTERNAL_DOWNLOADS]: The skill references well-known legal research services such as Westlaw, CourtListener, and Trellis. These are identified as legitimate, well-known services for the intended professional use case and do not involve the execution of untrusted remote code.
Audit Metadata