client-letter

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to assist law students in drafting routine correspondence like appointment confirmations and document requests using predefined templates.
  • [DATA_EXPOSURE]: The skill accesses local configuration files located at ~/.claude/plugins/config/claude-for-legal/legal-clinic/CLAUDE.md and directory-based practice guides. These file paths are specific to the skill's own configuration environment and do not target sensitive system credentials or private user data.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external case notes to populate fields within templates. While there are no explicit boundary markers for this data, the skill possesses no high-risk capabilities (such as network access or shell execution), limiting the impact of potential injection to the generated text draft which requires human review.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — client-letter