cold-call-prep

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill accesses a local configuration file located at ~/.claude/plugins/config/claude-for-legal/law-student/CLAUDE.md. This file contains user-specific context such as course lists and learning styles to personalize the training. This path belongs to the claude-for-legal suite developed by the same author, representing a standard integration for this ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of user-provided case text or reading materials to generate study questions. While it does not utilize explicit boundary markers to isolate this content, the skill lacks dangerous capabilities such as network operations or file-writing permissions, meaning the potential impact of an injection (e.g., trying to trick the agent into providing legal advice) is mitigated by existing procedural guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 01:02 AM
Security Audit — agent-trust-hub — cold-call-prep