cold-start-interview

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Vulnerability to indirect prompt injection exists in the data processing flow.
  • Ingestion points: The skill requests 5-10 recently signed agreements (seed files) from the user to analyze in SKILL.md (Step 3 and 4).
  • Boundary markers: There are no instructions to the agent to treat the content of these files as untrusted data or to ignore any embedded natural language instructions.
  • Capability inventory: The skill has the capability to write the extracted findings and rules into a persistent configuration file at ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md.
  • Sanitization: There is no evidence of sanitization or filtering of the content extracted from the contracts before it is saved to the 'living business domain configuration' which governs all other skills in the plugin.
  • [SAFE]: The skill accesses specific file paths such as ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md and ~/.claude/plugins/config/claude-for-legal/company-profile.md. These are considered safe as they are specific to the application's own configuration state and do not target generic sensitive system files or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — cold-start-interview