clearance
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection (Category 8) due to its integration of untrusted data from external sources into the triage process.
- Ingestion points: Untrusted data enters the context through trademark search results from external integrations (Solve Intelligence, CourtListener, Descrybe) and user-provided inputs in
SKILL.md. - Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings when interpolating retrieved trademark data into the final output memo.
- Capability inventory: The skill possesses the capability to write reports to the matter workspace and practice folders, and it can perform external network searches through available tool integrations.
- Sanitization: There is no evidence of sanitization or escaping of external content before it is processed and included in the triage results.
- [SAFE]: The skill performs legitimate file system operations, such as reading configuration from
CLAUDE.mdand writing triage memos to matter-specific folders within the~/.claude/plugins/config/claude-for-legal/ip-legal/directory. - [SAFE]: The skill includes extensive instructions for the AI to provide loud safety warnings and disclaimers, ensuring that the triage output is not misinterpreted as a professional legal clearance opinion.
Audit Metadata