closing-checklist
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill manages deal information using local files in the plugin configuration directory, which is appropriate for its deal-tracking functionality.
- [SAFE]: It includes a consequential-action gate requiring human legal review before final certifications, acting as a procedural safety measure to prevent unintended legal consequences.
- [SAFE]: The skill processes external documents (Purchase Agreements, Diligence memos), forming an indirect prompt injection surface. Ingestion points: External Purchase Agreements and output from other diligence skills like 'diligence-issue-extraction'. Boundary markers: No explicit delimiters for untrusted data were identified. Capability inventory: Actions are limited to file read and write operations within the local plugin scope (~/.claude/plugins/config/claude-for-legal/). Sanitization: No explicit content sanitization or filtering logic is present. This surface is necessary for the skill's core function and does not show evidence of malicious intent.
Audit Metadata