consulting-sow-risk-advisor
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's functionality is limited to natural language processing for contract review within a consulting context.
- [PROMPT_INJECTION]: The skill is designed to process external, user-provided Statements of Work (SOWs), which represents a potential surface for indirect prompt injection. However, the skill lacks the necessary capabilities (such as file system access, command execution, or network operations) to enable an exploit.
- Ingestion points: User-provided SOW text processed at runtime via prompts defined in SKILL.md.
- Boundary markers: Absent; the skill does not instruct the agent to use specific delimiters for external content.
- Capability inventory: The skill only performs text analysis and drafting; no subprocess calls, file writes, or network requests are present.
- Sanitization: No input validation or sanitization of the SOW content is specified.
Audit Metadata