hiring-review

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill reads from local configuration and case management files located at ~/.claude/plugins/config/claude-for-legal/ and within matter workspaces. This access is limited to its specific functional domain (employment law) and is used to retrieve jurisdiction-specific rules and matter context.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection as it processes untrusted offer letters provided by users. However, it implements robust mitigations, including strict source-citation requirements (e.g., [yuandian检索], [联网检索——需复核]), an instruction to never supplement missing research with model hallucination, and a mandatory 'Follow-up Action Threshold' that requires explicit confirmation of lawyer oversight before providing a final recommendation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — hiring-review