subpoena-triage
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No evidence of malicious intent, credential theft, or unauthorized remote code execution was found. The skill follows standard professional workflows for legal document processing.
- [PROMPT_INJECTION]: The skill features a surface for indirect prompt injection through the processing of untrusted subpoena documents provided by the user (Ingestion points: SKILL.md Step 1; Boundary markers: Absent; Capability inventory: File system read/write, interaction with legal research tools, and skill chaining via /legal-hold or /matter-intake; Sanitization: Absent). This is assessed as a low-risk surface inherent to the tool's primary function of document analysis.
- [DATA_EXFILTRATION]: The skill accesses sensitive local paths such as
~/.claude/plugins/config/claude-for-legal/to retrieve matter logs and privilege conventions. This access is localized and necessary for the intended functionality, with no identified mechanism for external data transmission beyond configured legal research tools. - [COMMAND_EXECUTION]: The skill performs command chaining to other internal skills (
/legal-hold,/matter-intake) and legal research tools. These are controlled hand-offs within a defined workspace environment.
Audit Metadata