subpoena-triage

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No evidence of malicious intent, credential theft, or unauthorized remote code execution was found. The skill follows standard professional workflows for legal document processing.
  • [PROMPT_INJECTION]: The skill features a surface for indirect prompt injection through the processing of untrusted subpoena documents provided by the user (Ingestion points: SKILL.md Step 1; Boundary markers: Absent; Capability inventory: File system read/write, interaction with legal research tools, and skill chaining via /legal-hold or /matter-intake; Sanitization: Absent). This is assessed as a low-risk surface inherent to the tool's primary function of document analysis.
  • [DATA_EXFILTRATION]: The skill accesses sensitive local paths such as ~/.claude/plugins/config/claude-for-legal/ to retrieve matter logs and privilege conventions. This access is localized and necessary for the intended functionality, with no identified mechanism for external data transmission beyond configured legal research tools.
  • [COMMAND_EXECUTION]: The skill performs command chaining to other internal skills (/legal-hold, /matter-intake) and legal research tools. These are controlled hand-offs within a defined workspace environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — subpoena-triage