chinese-legal-clinic
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill routes natural-language requests to multiple external domain files and processes their content without explicit sanitization or boundary markers.
- Ingestion points: Processes files such as legal-clinic/CLAUDE.md and legal-clinic/skills/*/SKILL.md, alongside natural language case data provided by the user.
- Boundary markers: The adapter lacks explicit delimiters or instructions to ignore embedded commands within the external legal content or user requests.
- Capability inventory: Performs local file system operations (read/write in ~/.codex and ~/.claude directories), utilizes web verification tools, and renders documents.
- Sanitization: No filtering or validation mechanisms are described for content retrieved from the referenced domain files.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill is designed to interact with configuration directories used by other AI agent platforms to facilitate interoperability.
- Evidence: Instructions specify reading from ~/.claude/plugins/config/ to import existing practice profiles and creating specific configuration files in ~/.codex/legal-zh/legal-clinic/CLAUDE.md.
Audit Metadata