chinese-legal-launch-radar

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructs the agent to perform local file reads and writes for "repositories, trackers, tables, and source documents." This capability is used to bridge external legal cookbooks into the local environment but involves broad file system access.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (source documents and trackers) to generate legal risk assessments, creating a surface for indirect prompt injection where malicious instructions in those documents could influence the agent's behavior.
  • Ingestion points: Local file reads of "source documents" and "trackers" as described in the How To Use section.
  • Boundary markers: The skill lacks explicit instructions or delimiters to isolate ingested document content from the agent's steering instructions.
  • Capability inventory: The agent is authorized to perform local file reads and writes across the project repository.
  • Sanitization: No sanitization or validation logic is defined for the external data ingested during the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:43 AM
Security Audit — agent-trust-hub — chinese-legal-launch-radar