bar-prep-questions

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a 'Real Case Check' safety mechanism. This pattern detects if a user is seeking actual legal advice rather than exam preparation and instructs the agent to refuse and provide referrals to legal aid or professional counsel.
  • [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface because it ingests data from external local files to customize the user's experience.
  • Ingestion points: The skill reads from ~/.claude/plugins/config/claude-for-legal/law-student/CLAUDE.md and study-plan.yaml.
  • Boundary markers: Absent; the skill does not explicitly define delimiters to distinguish instructions from the data loaded from these files.
  • Capability inventory: The skill has file-read and file-write capabilities restricted to the specific legal-student configuration directory.
  • Sanitization: The instructions do not specify any validation or sanitization steps for the content found within the configuration files.
  • [SAFE]: All external URL references target the official website of the Ministry of Justice of the People's Republic of China (moj.gov.cn), which is the authoritative source for the exam information described in the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:07 AM
Security Audit — agent-trust-hub — bar-prep-questions