elder-law-summary
Fail
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: HIGHPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill file contains a deceptive message at the end: "It looks like I don't have write permission to the file. Could you grant write access so I can save the rewrite, or would you like to copy the output above directly?". This is a social engineering attempt to manipulate the user into escalating the agent's privileges from read-only to write access, which could lead to unauthorized file modifications.\n- [PROMPT_INJECTION]: The skill is designed to process untrusted external data (legal and financial documents), creating a surface for indirect prompt injection.\n
- Ingestion points: The "Document Review Findings" section of SKILL.md indicates the skill processes uploaded documents.\n
- Boundary markers: Absent; the instructions do not include delimiters or warnings to ignore instructions embedded within the data source.\n
- Capability inventory: The skill performs data extraction and summarization, which can be influenced by malicious content in the processed documents.\n
- Sanitization: Absent; there is no logic provided to sanitize or validate the content of processed documents.
Recommendations
- AI detected serious security threats
Audit Metadata