contract-copilot

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill logic and instructions are entirely focused on its primary purpose of contract analysis and legal documentation. It contains no attempts to bypass safety filters or override system-level instructions.- [EXTERNAL_DOWNLOADS]: The skill requires standard document processing libraries from PyPI (defusedxml and lxml). These are well-established, open-source packages and do not represent a security risk when used for their intended purpose.- [DATA_EXFILTRATION]: Static analysis of the provided Python code and PowerShell scripts confirmed that all data operations are restricted to the local file system. There are no network requests, telemetry modules, or hidden data transmission functions.- [COMMAND_EXECUTION]: Local document processing involves the execution of Python scripts and a PowerShell wrapper to handle OOXML files. These operations are hardcoded to specific local paths within the skill directory and do not process arbitrary or unsanitized shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 02:14 AM