oc-status

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate automated drafting tasks using local files and integrated tools (Gmail MCP) within the user's authenticated environment.
  • [DATA_EXFILTRATION]: The skill reads legal matter context, including budget posture and upcoming deadlines, and sends this data to the Gmail API to create drafts. This is documented as the primary function of the skill and occurs only if the user has authenticated the Gmail integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect injection because it ingests untrusted data from matter.md and history.md files which may be updated from external sources.
  • Ingestion points: Reads matter context and history from local markdown and YAML files in ~/.claude/plugins/config/claude-for-legal/litigation-legal/.
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: File write operations and Gmail draft creation via MCP.
  • Sanitization: No specific sanitization or filtering of input data is described before interpolation into email drafts.
  • Note: The risk is mitigated by the requirement for human review before sending any generated drafts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — oc-status