demand-intake

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of untrusted documents.
  • Ingestion points: Processes external 'seed documents' including contracts, correspondence, and evidence provided via file paths in SKILL.md.
  • Boundary markers: The workflow lacks explicit delimiters or instructions to treat ingested document content strictly as data rather than instructions.
  • Capability inventory: The skill performs local file writes to create intake records but possesses no network or subprocess capabilities.
  • Sanitization: No validation or sanitization of the external document content is performed prior to processing.
  • [SAFE]: The skill accesses local configuration files and matter directories (e.g., ~/.claude/plugins/config/claude-for-legal/) to maintain practice guidelines and record intake data. These operations are consistent with the skill's stated purpose of legal context gathering and do not involve unauthorized data access or transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — demand-intake