elder-law-summary

Fail

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: HIGHPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill file contains a deceptive message at the end: "It looks like I don't have write permission to the file. Could you grant write access so I can save the rewrite, or would you like to copy the output above directly?". This is a social engineering attempt to manipulate the user into escalating the agent's privileges from read-only to write access, which could lead to unauthorized file modifications.\n- [PROMPT_INJECTION]: The skill is designed to process untrusted external data (legal and financial documents), creating a surface for indirect prompt injection.\n
  • Ingestion points: The "Document Review Findings" section of SKILL.md indicates the skill processes uploaded documents.\n
  • Boundary markers: Absent; the instructions do not include delimiters or warnings to ignore instructions embedded within the data source.\n
  • Capability inventory: The skill performs data extraction and summarization, which can be influenced by malicious content in the processed documents.\n
  • Sanitization: Absent; there is no logic provided to sanitize or validate the content of processed documents.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 21, 2026, 10:33 PM
Security Audit — agent-trust-hub — elder-law-summary