demand-draft

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill's file operations and tool interactions are limited to specific legal project directories and the generation of document drafts, which align with its intended functional purpose.
  • [SAFE]: The skill processes untrusted data from intake files (intake.md). While this constitutes a potential indirect prompt injection surface, the risk is mitigated by a multi-step human-in-the-loop review process and mandatory safety gates. Ingestion points: ~/.claude/plugins/config/claude-for-legal/litigation-legal/demand-letters/[slug]/intake.md. Boundary markers: None explicitly defined for input. Capability inventory: File system writes and tool calls to the docx skill. Sanitization: Performed through iterative human review and manual approval checkpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — demand-draft