legal-case-analysis
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as case materials, evidence documents, and contracts. This presents an indirect prompt injection surface. However, the risk is mitigated by explicit instructions requiring the agent to distinguish between evidence and client statements, verify facts against materials, and mark missing information rather than hallucinating. The multi-step legal frameworks provided (e.g., the nine-step civil litigation and two-layer criminal analysis) act as strong boundary markers for logical consistency.
- [EXTERNAL_DOWNLOADS]: The skill mentions and recommends using specific external tools such as 'yuandian-law-search', 'zhihe-legal-research', and OCR tools ('MinerU', 'PaddleOCR'). These references are informative for the legal workflow and do not involve unauthorized script execution or hidden downloads.
- [COMMAND_EXECUTION]: No evidence of silent shell command execution, dynamic context injection, or unauthorized subprocess calls was found. The instructions focus on markdown-based reporting and data organization.
Audit Metadata