demand-draft
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's file operations and tool interactions are limited to specific legal project directories and the generation of document drafts, which align with its intended functional purpose.
- [SAFE]: The skill processes untrusted data from intake files (intake.md). While this constitutes a potential indirect prompt injection surface, the risk is mitigated by a multi-step human-in-the-loop review process and mandatory safety gates. Ingestion points:
~/.claude/plugins/config/claude-for-legal/litigation-legal/demand-letters/[slug]/intake.md. Boundary markers: None explicitly defined for input. Capability inventory: File system writes and tool calls to thedocxskill. Sanitization: Performed through iterative human review and manual approval checkpoints.
Audit Metadata