chinese-legal-ai-governance
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads configuration profiles from
~/.claude/plugins/config/and~/.codex/legal-zh/ai-governance-legal/CLAUDE.md. This access is functional, intended to migrate or maintain user practice settings between different AI platform environments (Claude and Codex), and does not target sensitive system credentials or perform unauthorized exfiltration.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from user-supplied legal documents and external web verification sources.\n - Ingestion points: Natural language requests, AI application scenarios, and web verification data (SKILL.md).\n
- Boundary markers: Explicitly instructs the agent to preserve escalation, approval, and confidentiality requirements from the original domain workflows.\n
- Capability inventory: File access for local configuration, web verification for legal facts, and document rendering (SKILL.md).\n
- Sanitization: Mitigates risks by mandating that all outputs be marked as drafts requiring professional lawyer review and requiring verification of time-sensitive facts before reliance.
Audit Metadata