nda-generator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a standard document generation assistant. It uses a specific set of tools (create_docx, fill_docx_template, docx_to_pdf) to perform its stated functions. The instructions are clear, helpful, and contain no prompt injection or exfiltration patterns. External references are limited to legitimate project documentation and examples.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles user-provided data such as party names and business contexts to generate documents. This represents a theoretical attack surface common to all LLM document generation tasks. However, the risk is negligible as the tools used are limited to local document formatting and conversion, and the skill does not grant the agent high-privilege access or network capabilities that could be abused via injected content.
  • Ingestion points: User-provided situation details and party names described in SKILL.md.
  • Boundary markers: None explicitly defined to delimit user input from instructions.
  • Capability inventory: The skill utilizes document creation and conversion tools from the specified MCP server.
  • Sanitization: No explicit sanitization of user input is specified before interpolation into templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:53 PM
Security Audit — agent-trust-hub — nda-generator