brief-section-drafter

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses local configuration and log files located at ~/.claude/plugins/config/claude-for-legal/ to retrieve case theory, firm styles, and matter logs. These accesses are scoped to the plugin's internal configuration and are used to enforce a 'conflicts gate' (verifying the matter is intaken before drafting). No network exfiltration of this data was detected.
  • [PROMPT_INJECTION]: The skill processes potentially untrusted external data, such as case chronologies and document sets, which presents a surface for indirect prompt injection. This risk is mitigated through robust instructional guardrails, including mandatory citation markers ([VERIFY], [CITE NEEDED]), explicit warnings about Rule 11 sanctions, and strict requirements for human attorney review before any output is finalized or filed.
  • [EXTERNAL_DOWNLOADS]: The skill references well-known legal research services such as Westlaw, CourtListener, and Trellis. These are identified as legitimate, well-known services for the intended professional use case and do not involve the execution of untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — brief-section-drafter