chinese-legal-regulatory
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructs the agent to read existing Claude plugin configuration profiles located at
~/.claude/plugins/config/. This is performed to inherit the user's established legal practice settings for the new adapter. Although this involves accessing paths within the user's home directory, the scope is limited to application-specific configuration for the purpose of tool interoperability. - [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting content from external files within a local domain directory (
regulatory-legal/). This setup creates an ingestion surface for potentially untrusted data. However, this is the intended primary function of the adapter, and the instructions include explicit 'Legal Output Rules' that mandate verification of all citations and citations of time-sensitive legal facts, which acts as a procedural safeguard.
Audit Metadata