vendor-ai-review

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's operations are restricted to its internal plugin configuration and matter-specific data paths within ~/.claude/plugins/config/claude-for-legal/.
  • [SAFE]: No network operations, external downloads, or remote code execution patterns were identified.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (vendor contracts), which constitutes an indirect prompt injection surface.
  • Ingestion points: User-provided vendor terms (PDF attachments or pasted text).
  • Boundary markers: None explicitly defined to isolate document content from instructions.
  • Capability inventory: Read/write access to local plugin files; no network or subprocess capabilities available.
  • Sanitization: Not described.
  • Assessment: The risk is low because the skill's output is purely informational (analysis and redlines) and it lacks the capabilities to perform sensitive actions if an injection occurs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:57 PM
Security Audit — agent-trust-hub — vendor-ai-review