nda-triage

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an attack surface for indirect prompt injection by processing and triaging untrusted external document files.
  • Ingestion points: The analytical scripts scripts/nda_screener.py and scripts/nda_checklist.py ingest the entire content of user-provided NDA text files.
  • Boundary markers: The skill does not implement explicit boundary markers or instructions to the agent to ignore potentially malicious instructions embedded within the NDA content.
  • Capability inventory: The triage tools are limited to local file system read operations and analysis. No network communication, external package dependencies, or dynamic code execution capabilities (eval/exec) were detected.
  • Sanitization: The input text is processed directly using regular expression matching without prior sanitization or filtering, which could allow adversarial document formatting to manipulate the screening results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:57 PM
Security Audit — agent-trust-hub — nda-triage