irac-practice
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely locally, managing student outlines and session history within a specific plugin configuration path (~/.claude/plugins/config/claude-for-legal/).
- [PROMPT_INJECTION]: The skill ingests user essays, which are untrusted data. While this creates a surface for indirect prompt injection, the skill's capabilities are restricted to generating textual feedback and writing to a local session tracker, with no access to network operations or system commands to exploit.
- [DATA_EXFILTRATION]: The skill reads from and appends to local files within its own configuration directory. There are no network operations or attempts to transmit data to external domains.
Audit Metadata