customize

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to manage local configuration state for a legal-specific agent. It follows a structured workflow to read, modify, and confirm changes to user preferences.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses and updates files located at ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md and company-profile.md. These paths are dedicated to the plugin's own configuration management. There are no patterns suggesting exfiltration of sensitive data to external servers or access to critical system files like SSH keys or environment variables.
  • [COMMAND_EXECUTION]: The skill does not contain any instructions to execute shell commands, subprocesses, or external scripts. Its operations are limited to text-based file reading and writing within its defined scope.
  • [INDIRECT_PROMPT_INJECTION]: While the skill reads external configuration files that could theoretically contain untrusted content, the risk is minimized by the guided nature of the interaction. The skill explicitly instructs the agent to show current values, ask for new values, and explain impacts before performing updates, maintaining a human-in-the-loop verification process.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — customize