legal-risk-assessment
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data from risk register files which could be manipulated to influence agent behavior.
- Ingestion points: The scripts
scripts/risk_report_generator.pyandscripts/risk_scorer.pyboth ingest external data from JSON files provided via the--inputargument. - Boundary markers: The instructions lack explicit boundary markers or directives for the agent to ignore instructions embedded within the processed risk data (e.g., in the 'description' field).
- Capability inventory: The skill includes tools capable of reading and writing files to the local filesystem (
risk_report_generator.py --output). - Sanitization: While the scripts perform basic schema validation (checking for required fields and value ranges), they do not sanitize string content for natural language instruction payloads that could target the LLM during subsequent analysis of the generated memos.
Audit Metadata