chinese-legal-clinic

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill routes natural-language requests to multiple external domain files and processes their content without explicit sanitization or boundary markers.
  • Ingestion points: Processes files such as legal-clinic/CLAUDE.md and legal-clinic/skills/*/SKILL.md, alongside natural language case data provided by the user.
  • Boundary markers: The adapter lacks explicit delimiters or instructions to ignore embedded commands within the external legal content or user requests.
  • Capability inventory: Performs local file system operations (read/write in ~/.codex and ~/.claude directories), utilizes web verification tools, and renders documents.
  • Sanitization: No filtering or validation mechanisms are described for content retrieved from the referenced domain files.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill is designed to interact with configuration directories used by other AI agent platforms to facilitate interoperability.
  • Evidence: Instructions specify reading from ~/.claude/plugins/config/ to import existing practice profiles and creating specific configuration files in ~/.codex/legal-zh/legal-clinic/CLAUDE.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:43 AM
Security Audit — agent-trust-hub — chinese-legal-clinic