cold-call-prep
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill accesses a local configuration file located at
~/.claude/plugins/config/claude-for-legal/law-student/CLAUDE.md. This file contains user-specific context such as course lists and learning styles to personalize the training. This path belongs to theclaude-for-legalsuite developed by the same author, representing a standard integration for this ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of user-provided case text or reading materials to generate study questions. While it does not utilize explicit boundary markers to isolate this content, the skill lacks dangerous capabilities such as network operations or file-writing permissions, meaning the potential impact of an injection (e.g., trying to trick the agent into providing legal advice) is mitigated by existing procedural guardrails.
Audit Metadata