feature-risk-assessment

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates within a restricted workspace environment, accessing specific application configuration files (CLAUDE.md) and matter-specific documents (matter.md) to maintain professional context. It does not access sensitive system credentials or perform unauthorized network operations.\n- [PROMPT_INJECTION]: The skill processes data from external legal databases and model knowledge, but incorporates defenses against indirect injection. It requires the agent to tag every citation with its specific source (e.g., [北大法宝], [模型知识]) and explicitly forbids 'silent filling' of missing information from unverified sources.\n
  • Ingestion points: Matter files and external legal research tool outputs.\n
  • Boundary markers: Mandatory source attribution tags serve as semantic boundaries.\n
  • Capability inventory: File write access is limited to the defined plugin matter directory.\n
  • Sanitization: Requires manual verification of citations against authoritative databases before finalization.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — feature-risk-assessment