ai-tool-handoff
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill accesses local configuration files and sensitive legal documents within the
~/.claude/plugins/config/claude-for-legal/directory structure. This file access is central to its stated purpose of managing legal due diligence matters and matter-specific contexts. - [INDIRECT_PROMPT_INJECTION]: The skill processes external legal documents (data room documents) which are untrusted inputs. While these could theoretically contain adversarial content, the skill includes a specific Quality Assurance (QA) layer (sampling, error rate checks, and human review tiers) that mitigates the risk of the agent blindly following instructions embedded in documents.
- [EXTERNAL_DOWNLOADS]: The instructions mention external legal AI tools (Luminance, Kira), but the skill does not automate network requests to these tools; it generates instructions for a human user to perform the handoff, maintaining a human-in-the-loop safety model.
Audit Metadata