socratic-drill

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses student profile data (learning styles, class information, and academic weak areas) from the configuration file at ~/.claude/plugins/config/claude-for-legal/law-student/CLAUDE.md. This data is used locally to personalize the tutoring experience and is not transmitted externally.
  • [PROMPT_INJECTION]: The skill ingests untrusted user content (notes, outlines, case briefs, and flashcards) to identify reasoning contradictions.
  • Ingestion points: User study materials referenced in the CLAUDE.md configuration file.
  • Boundary markers: No explicit delimiters are used to separate user-provided content from system instructions.
  • Capability inventory: The skill is limited to reading files and interactive dialogue; it lacks capabilities for network operations, file system modifications, or shell command execution.
  • Sanitization: No validation or sanitization is performed on the ingested materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — socratic-drill