demand-intake

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely within the local file system, specifically under the plugin's configuration directory (~/.claude/plugins/config/claude-for-legal/).- [DATA_EXPOSURE]: While the skill collects sensitive legal information (facts, strategies, and evidence), this is the primary purpose of the tool and the data remains within the local environment.- [SAFE]: No remote code execution, external downloads, or network operations are present. The skill uses standard local file management practices for data persistence.- [INDIRECT_PROMPT_INJECTION]: The skill processes user input and writes it to a markdown file for later reading by other skills. Although it lacks explicit boundary markers to delimit user data in the generated file, the risk is negligible as the operations are local and triggered by the user for their own professional context.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — demand-intake