chinese-legal-employment
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes natural language requests for legal drafting, creating a surface for indirect prompt injection. Ingestion points: Natural language requests for legal work (SKILL.md). Boundary markers: None. Capability inventory: Local file access, web verification, and document rendering (SKILL.md). Sanitization: None.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses tool-specific configuration profiles in the user's home directory (~/.claude/plugins/config/ and ~/.codex/legal-zh/). This is standard practice for adapter skills to maintain user state and preferences.
Audit Metadata