matter-briefing

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes narrative legal text from local files without using boundary markers, which creates an indirect prompt injection surface. An adversary could attempt to influence the agent's behavior by embedding instructions in the matter files. \n
  • Ingestion points: Narrative intake and history files (matter.md, history.md) located in ~/.claude/plugins/config/claude-for-legal/litigation-legal/matters/. \n
  • Boundary markers: The instructions lack delimiters or explicit directives to ignore instructions within the processed data files. \n
  • Capability inventory: The skill is limited to file reading and text output; it possesses no network access, shell command execution, or other high-privilege tool capabilities. \n
  • Sanitization: No sanitization or instruction filtering is applied to the content read from the files. \n- [NO_CODE]: The skill consists entirely of markdown instructions and configuration and does not include any executable scripts, binaries, or logic in external code files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — matter-briefing