ai-tool-handoff

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill accesses local configuration files and sensitive legal documents within the ~/.claude/plugins/config/claude-for-legal/ directory structure. This file access is central to its stated purpose of managing legal due diligence matters and matter-specific contexts.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external legal documents (data room documents) which are untrusted inputs. While these could theoretically contain adversarial content, the skill includes a specific Quality Assurance (QA) layer (sampling, error rate checks, and human review tiers) that mitigates the risk of the agent blindly following instructions embedded in documents.
  • [EXTERNAL_DOWNLOADS]: The instructions mention external legal AI tools (Luminance, Kira), but the skill does not automate network requests to these tools; it generates instructions for a human user to perform the handoff, maintaining a human-in-the-loop safety model.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — ai-tool-handoff