ai-inventory
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a structured workflow for AI system classification and regulatory mapping. All operations are local and consistent with its documentation.
- [DATA_EXPOSURE]: The skill reads from and writes to
~/.claude/plugins/config/claude-for-legal/, which is a specific configuration directory for the legal plugin. This access is necessary for maintaining the AI system inventory and does not target sensitive system files or credentials. - [PROMPT_INJECTION]: The skill processes user-supplied system descriptions and data from
CLAUDE.md. While this data is integrated into the assessment workflow, the instructions focus on structured data extraction and classification, which minimizes the risk of instruction override. The skill functions as an audit tool where processing user-provided descriptions is the intended primary purpose.
Audit Metadata