hiring-review

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a strict 'No silent supplement' policy that prevents the agent from filling information gaps using its own training data or unauthorized web searches. This significantly reduces the risk of hallucinations and ensures the agent remains grounded in verifiable research tools.
  • [SAFE]: The skill includes a 'consequential-action gate' that detects if the user is a non-lawyer. It provides appropriate warnings about the legal consequences of offer letters and directs users to qualified legal counsel, demonstrating high safety awareness for high-stakes tasks.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (offer letters) as specified in the argument-hint. While this is a potential attack surface for indirect prompt injection, the skill mitigates this by enforcing a rigid, multi-step analytical workflow (Jurisdiction, Classification, Restrictive Covenants) that requires independent research and source tagging ([Westlaw], [CourtListener], etc.).
  • [DATA_EXFILTRATION]: The skill accesses files within a specific local directory (~/.claude/plugins/config/claude-for-legal/). This access is scoped to its stated purpose of managing legal matter workspaces and jurisdictional footprints. There is no evidence of unauthorized file access or network exfiltration to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — hiring-review