legal-hold
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates exclusively on local file paths within its designated configuration directory (~/.claude/plugins/config/claude-for-legal/). Access is restricted to matter-specific logs, templates, and history files.
- [SAFE]: There are no detected network communication patterns, such as curl, wget, or API requests, which prevents data exfiltration to external domains.
- [SAFE]: The skill incorporates mandatory security and compliance gates, including a conflicts check that requires matters to be properly intaken before any actions are performed.
- [SAFE]: It implements a "Who's using this" check that differentiates between lawyers and non-lawyers, requiring explicit user confirmation before high-stakes legal actions (issuing or releasing holds) are simulated.
- [SAFE]: File writing is limited to structured updates in YAML logs and the generation of .docx files via a separate document skill, with no evidence of dynamic code generation or shell command execution.
Audit Metadata